CVE-2026-14802Disclosure

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-06: 3Active Exploitation · 2026-07-06: 1Patch / Workaround · 2026-07-06: 2Technical Details · 2026-07-06: 307-06
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
Full discourse3 posts
  • AlexAImaginator@TraffAlex
    Active Exploitation

    🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — July 06, 2026 1️⃣ CRITICAL ADOBE COLDFUSION FLAW (CVSS 10.0) NOW BEING ACTIVELY EXPLOITED A maximum-severity path traversal vulnerability, CVE-2026-48282, has been discovered in Adobe ColdFusion affecting versions 2025.9, 2023.20, and earlier. The flaw enables unauthenticated remote code execution, and the Canadian Centre for Cyber Security has confirmed open-source reports of active exploitation in the wild. Adobe released an emergency patch with 72-hour priority response — any organization running ColdFusion should update immediately. 🔹 @seoscottsdale 2️⃣ GITEA CRITICAL ACCESS CONTROL VULNERABILITY (CVSS 9.8) Gitea versions prior to 1.26.3 and 1.26.4 contain a critical improper access control flaw, CVE-2026-20896, with a CVSS score of 9.8. The vulnerability allows an attacker to impersonate any user by crafting malicious reverse-proxy headers. This affects self-hosted Git instances widely used in development teams. Gitea released security patches in both 1.26.3 and 1.26.4 — upgrade paths are available and should be applied without delay. 🔹 @CCBalert 3️⃣ CREATE-REACT-APP RCE VULNERABILITY — NO PATCH COMING CVE-2026-14802 affects create-react-app (CRA) with a command injection vulnerability in the startBrowserProcess function on macOS, rated CVSS 7.3. The critical issue: CRA is officially deprecated and no security patch will ever be released. The only remediation is to migrate projects to Vite, Next.js, or other actively maintained build tools. If you're still running CRA in any environment, this is your warning. 🔹 @ThreatAft 4️⃣ QILIN RANSOMWARE STRIKES MULTIPLE US COMPANIES IN SINGLE DAY The Qilin ransomware group has claimed responsibility for at least three attacks on July 6 alone: Keystone Homes in the construction sector, Answer Precision Tool, and Precision Steel Services. These coordinated strikes across the manufacturing and construction industries suggest Qilin is scaling its operations with targeted sector campaigns. Dark web monitoring teams are tracking the group's leak sites for exfiltrated data patterns. 🔹 @TMRansomMon 5️⃣ CLICKFIX SCAMS ABUSE GOOGLE AND CLOUDFLARE VERIFICATION TO DELIVER 7 MALWARE FAMILIES Security researchers uncovered a sophisticated ClickFix tech support scam operation that abuses Google and Cloudflare verification systems to appear legitimate. By exploiting trusted infrastructure indicators, the campaign delivers at least seven distinct malware families to victims who fall for fake error prompts. The attack highlights how threat actors increasingly weaponize trusted brand signals to bypass user skepticism. 🔹 @VivekIntel 6️⃣ LINUX KERNEL "BAD EPOLL" VULNERABILITY ENABLES LOCAL PRIVILEGE ESCALATION CVE-2026-46242 is a critical Use-After-Free vulnerability in the Linux kernel's epoll subsystem with a CVSS score of 7.8. Known as BadEpoll, the flaw allows local unprivileged users to escalate privileges to root on both Linux and Android systems. The vulnerability stems from a race condition combined with improper cleanup logic. System administrators should prioritize kernel updates across all affected distributions. 🔹 @CCBalert 7️⃣ HOTELS TARGETED BY MYSTERIOUS FAKE GUEST COMPLAINT EMAILS INSTALLING MALWARE The hospitality industry is facing a new wave of targeted phishing attacks where hotels receive emails appearing to be guest complaints. Opening the attachments installs malware on hotel systems, but the幕后 threat actor and motive remain unidentified. The campaign's specificity — targeting front desk and management staff — suggests insider knowledge of hotel operations and communication workflows. 🔹 @garyleff 8️⃣ 82% OF THREAT DETECTIONS WERE MALWARE-FREE IN 2025, CROWDSTRIKE GTR REPORT According to the CrowdStrike 2026 Global Threat Report, an overwhelming 82% of threat detections in 2025 were malware-free. This means most real-world adversary activity relies on living-off-the-land techniques, legitimate tools, and fileless execution. Organizations that base their detection rules primarily on malicious binary indicators are only covering the minority of actual attack patterns — a critical gap in modern defense strategies. 🔹 @scythe_io 💭 The cybersecurity landscape on July 6 underscores a troubling trend: critical infrastructure is being hit from multiple angles simultaneously. From maximum-severity CVEs in widely deployed software to ransomware groups operating with industrial precision, the attack surface continues to expand faster than patch cycles can keep up. The CrowdStrike finding that 82% of detections are now malware-free should be a wake-up call for security teams still relying on traditional signature-based defenses. Which of these vulnerabilities is your team patching first today? 👇 #Cybersecurity #InfoSec #Ransomware #CVE #OpenSource #ThreatIntel

    Post summary

    The post highlights multiple critical CVEs with confirmed active exploitation, providing detailed technical information and urging immediate patching of affected systems.

    10000361
    2.6K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 HIGH: CVE-2026-14802 — create-react-app RCE CVSS 7.3. Command injection via startBrowserProcess on macOS. ⚠️ NO PATCH WILL COME — CRA is DEPRECATED. Migrate to Vite or Next.js NOW. 🔗 https://threataft.com/articles/cve-2026-14802-create-react-app-command-injection?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #infosec #React #javascript

    Post summary

    The post announces that CVE‑2026‑14802 is a high‑severity RCE in create‑react‑app with no available patch, urging users to migrate to alternative frameworks.

    0000071
    32 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - macOS OS command injection via CRA openBrowser startBrowserProcess (CVE-2026-14802) A command injection flaw exists in create-react-app’s macOS browser-launching path, specifically the startBrowserProcess function in react-dev-utils (openBrowser.js). The root cause is improper input validation/unsafe command construction when invoking OS-level browser launch commands. An attacker can exploit this remotely by controlling or influencing inputs that flow into the dev server’s browser-opening logic on a developer machine (e.g., crafted values that reach openBrowser), with no local admin privileges required beyond the developer running the dev environment. Successful exploitation can lead to arbitrary OS command execution under the developer’s user context, enabling code execution, credential theft, and lateral movement from the compromised workstation. 👉 Affected: create-react-app <= 5.0.1 (macOS) | No fix yet — treat as suspicious

    Post summary

    A newly disclosed OS command injection flaw (CVE-2026-14802) in create‑react‑app’s macOS browser‑launching path can enable remote command execution under a developer’s user context, and no patch has been released yet.

    00000105
    239 followersView on X

Explore more