CVE-2026-2417Disclosure

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-24); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1Mentions · 2026-03-28: 1Active Exploitation · 2026-03-25: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-28: 103-2403-2503-28
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-241
Disclosure1
2026-03-251
Active Exploitation1
2026-03-281
Disclosure1
Full discourse3 posts
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة خطيرة CVSS 9.8 في وحدات تحكم Pharos Mosaic تمنح وصول Root لمهاجمين غير موثقين أصدرت CISA تحذيراً أمنياً بشأن ثغرة حرجة (CVE-2026-2417) في برامج Pharos Controls’ Mosaic Show Controller. تستغل هذه الثغرة، المصنفة CVSS 9.8، ضعفاَ من نوع (stack-based buffer overflow) يمكن المهاجمين غير الموثقين من الحصول على صلاحيات (root access). يتيح هذا الوصول غير المصرح به التحكم الكامل بالأنظمة المتأثرة، مما يشكل خطراً فادحاً على البنية التحتية التشغيلية. 🔗 للمزيد: https://securityonline.info/pharos-mosaic-show-controller-critical-vulnerability-cve-2026-2417/

    Post summary

    CISA warns of a critical CVE‑2026‑2417 vulnerability in Pharos Controls’ Mosaic Show Controller, a stack‑based buffer overflow that could grant attackers root privileges. No evidence of active exploitation or patch information is provided.

    00040656
    96 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting missing authentication in Pharos Controls Mosaic Show Controller (CVE-2026-2417) to gain root access and move laterally across networked devices. Runtime segmentation could help contain such post-compromise activity in industrial environments. #ZeroTrust #Vulnerability 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/pharos-controls-mosaic-show-controller-2026-missing-authentication

    Post summary

    The post confirms that CVE-2026-2417, a missing‑authentication flaw in Pharos Controls Mosaic Show Controller, is actively exploited to gain root access and pivot laterally across devices, highlighting a risk in industrial environments.

    0000052
    1.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-2417: Missing Authentication for Critic... Unauthenticated root RCE on network-accessible show controllers - every venue running Pharos 2.15.3 is a sitting duck fo... https://zerodaysignal.com/vulnerability/CVE-2026-2417 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑2417, identifies it as an unauthenticated root RCE affecting Pharos 2.15.3 controllers, but does not disclose PoC, exploit code, or active exploitation evidence.

    0000083
    164 followersView on X

Explore more