CVE-2026-2553General

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /home.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Name/Email results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-17: 1Technical Details · 2026-02-17: 102-1602-17
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-161
General1
2026-02-171
Disclosure1
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 17, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. CVE-2026-2553: SQL Injection in tushar-2223 Hotel-Management-System home.php A remote SQL injection vulnerability exists in the HTTP POST handler of the tushar-2223 Hotel-Management-System's home.php file. Manipulating the Name or Email parameters allows attackers to execute arbitrary SQL commands. The exploit is publicly available, increasing the risk of active attacks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2553 3. Malicious Chrome Extension Steals 2FA and Analytics from Facebook Business Manager A deceptive Chrome extension posing as a Meta Business Suite productivity tool is actively stealing Two-Factor Authentication (2FA) seeds, one-time codes, and sensitive business analytics from Facebook Business Manager accounts. This exposes users to account takeover risks despite the presence of 2FA protections. Sources: Gbhackers, Therecord https://gbhackers.com/malicious-chrome-extension-exposes-facebook-manager/ 4. Lotus Blossom Hackers Compromise Notepad++ Update Infrastructure for Espionage Between June and December 2025, the state-sponsored Lotus Blossom group breached the official Notepad++ update hosting infrastructure, enabling them to deliver malicious payloads through trusted developer tool updates. This compromise poses significant risks to users by turning a widely used software update channel into an espionage vector. Sources: Cvefeed, Gbhackers https://gbhackers.com/notepad-breached/ 5. Multiple Remote Code Execution and Injection Vulnerabilities Disclosed in Popular Software Several critical and medium severity vulnerabilities have been disclosed affecting multiple software products including LigeroSmart, yued-fe LuLu UI, vichan-devel, Comfast CF-E4, and others. These include remote code execution via command injection, cross-site scripting, and unverified password changes, with some exploits publicly available, increasing the risk of active attacks. Sources: Cvefeed, Gbhackers, Sans https://cvefeed.io/vuln/detail/CVE-2026-2545 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article reports several new CVEs with detailed technical descriptions, but does not provide proof‑of‑concepts, exploitation code, or evidence of active attacks.

    0001055
    54 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2553 A security flaw has been discovered in tushar-2223 Hotel-Management-System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. This affects an unknown part of the file /hom… https://www.cve.org/CVERecord?id=CVE-2026-2553

    Post summary

    A brief disclosure notes the existence of CVE-2026-2553 in a hotel‑management system, but provides minimal technical detail and no information about PoC, exploit, or mitigation.

    00000470
    56.4K followersView on X

Explore more