CVE-2026-24663Disclosure(copeland / xweb_300d_pro)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch copeland xweb_300d_pro systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xweb_300d_pro
  • xweb_300d_pro_firmware
  • xweb_500b_pro
  • xweb_500b_pro_firmware

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-27); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
xweb_300d_proxweb_300d_pro_firmwarexweb_500b_proxweb_500b_pro_firmwarexweb_500d_proxweb_500d_pro_firmware

1 version affected across 6 products

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-27: 5Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-02-27: 2Technical Details · 2026-02-27: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2703-0303-0405-06
Signal classification3 categories
Disclosure
450.0%
General
225.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-275
Disclosure2General1Patch2
2026-03-031
Disclosure1
2026-03-041
Disclosure1
2026-05-061
General1
Full discourse8 posts
  • Wavasec@wavasec
    General

    Critical Apache HTTP2 Flaw CVE-2026-24663 #CyberSecurity #CyberSecurityNews #InfoSec #Pentesting https://blog.wavasec.com/critical-apache-http2-flaw-cve-2026-24663/ https://t.co/w45rmR7rKB

    Post summary

    The tweet announces a new critical Apache HTTP2 vulnerability (CVE‑2026‑24663) and links to a blog for more details, but provides no evidence of PoC, exploit code, active attacks, or fixes.

    0000073
    7 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24663 (CVSS:9.0, CRITICAL) is Undergoing Analysis. An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker..https://nvd.nist.gov/vuln/detail/CVE-2026-24663 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-24663, a critical OS command injection flaw in XWEB Pro 1.12.1 and earlier, allowing unauthenticated attackers, with no PoC, exploit, or patch mentioned.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24663 (CVSS:9.0, CRITICAL) is Undergoing Analysis. An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker..https://nvd.nist.gov/vuln/detail/CVE-2026-24663 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-24663, a critical OS command injection flaw in XWEB Pro 1.12.1 and earlier, with no mention of PoC, exploit, or patch.

    0000042
    173 followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting Copeland XWEB 300D PRO and other products (CVE-2026-24663) https://vuldb.com/?id.348115

    Post summary

    A brief announcement of a vulnerability (CVE-2026-24663) affecting Copeland XWEB 300D PRO, linking to a vulnerability database entry.

    0000063
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24663 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the syst… https://www.cve.org/CVERecord?id=CVE-2026-24663

    Post summary

    The snippet announces a new OS command injection vulnerability in XWEB Pro 1.12.1 and earlier, noting its potential for remote code execution by unauthenticated attackers.

    00000145
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24663: CRITICAL] Critical OS command injection vulnerability found in XWEB Pro v1.12.1 & earlier versions allows unauthenticated attackers remote code execution. Update recommended ASAP.#cve,CVE-2026-24663,#cybersecurity https://cvefind.com/CVE-2026-24663

    Post summary

    The post discloses a critical OS command injection flaw (CVE-2026-24663) in XWEB Pro that permits unauthenticated remote code execution and urges users to apply an update immediately.

    0000048
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-24663** is a critical OS command injection vulnerability found in **XWEB Pro** versions **1.12.1 and earlier**. This flaw allows an **unauthenticated attacker** to remotely execute arbitrary system commands by exploiting the way the application processes requests sent to its libraries installation route. The attacker can craft malicious input within the request body, leading to remote code execution (RCE). #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #Apple https://cvetodo.com/cve/CVE-2026-24663

    Post summary

    A critical OS command injection vulnerability (CVE‑2026‑24663) in XWEB Pro allows unauthenticated attackers to execute arbitrary system commands via crafted requests to the libraries installation route.

    0000040
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-24663 in Copeland XWEB 300D PRO lets unauth'd attackers run remote code via command injection. No patch yet — segment networks & restrict access now! 🛡️ https://radar.offseq.com/threat/cve-2026-24663-cwe-78-in-copeland-copeland-xweb-30-1c773deb #OffSeq #IC... https://t.co/ii2JpP9CbU

    Post summary

    A new CVE-2026-24663 allows unauthenticated attackers to execute remote code on Copeland XWEB 300D PRO devices via command injection; no patch is available yet, so users should segment networks and restrict access.

    0000035
    270 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWcopelandxweb_300d_pro---
OScopelandxweb_300d_pro_firmware---
HWcopelandxweb_500b_pro---
OScopelandxweb_500b_pro_firmware---
HWcopelandxweb_500d_pro---
OScopelandxweb_500d_pro_firmware---

Explore more