CVE-2026-26068Disclosure(jm33-m0 / emp3r0r)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch jm33-m0 emp3r0r systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • emp3r0r

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-13); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
emp3r0r

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-12: 1Mentions · 2026-02-13: 2Mentions · 2026-02-15: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 202-1202-1302-15
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-02-132
Disclosure2
2026-02-152
Disclosure1Patch1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-26068 emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during che… https://www.cve.org/CVERecord?id=CVE-2026-26068

    Post summary

    CVE-2026-26068 relates to emp3r0r accepting untrusted agent metadata before version 3.21.1; the post lacks PoC, exploit, patch, or active exploitation details.

    00010273
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26068: emp3r0r Agent-Controlled Metadat... Command injection via unchecked agent metadata flips the script on emp3r0r C2 operators - your Linux stealth framework ... https://zerodaysignal.com/vulnerability/CVE-2026-26068 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-26068, a command injection vulnerability in emp3r0r's metadata handling, with no mention of exploits, patches, or PoC details.

    0000069
    131 followersView on X
  • Cybersecurity Aide@SecAideInfo
    Patch

    🚨🔒 #CyberAlert: CVE-2026-26068 is critical! Affects #emp3r0r C2 server (pre-3.21.1), allowing command injection & RCE via agent metadata. Linux operators, update to 3.21.1 NOW to secure your systems! 💻🔧 #Linux #Infosec #RCE #PatchNow #CyberSecurity #StaySafe

    Post summary

    CVE-2026-26068 enables command injection and RCE on emp3r0r C2 (pre‑3.21.1) via agent metadata; operators are urged to update to version 3.21.1 to apply the fix.

    0000014
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-26068 in jm33-m0 emp3r0r (<3.21.1) allows unauthenticated RCE via command injection on Linux operator hosts. Upgrade ASAP to stay secure! 🔒 https://radar.offseq.com/threat/cve-2026-26068-cwe-77-improper-neutralization-of-s-58777eec #OffSeq #Cybersecurity #... https://t.co/ADHJxpoz4v

    Post summary

    CVE-2026-26068 is a critical vulnerability that allows unauthenticated remote code execution via command injection on Linux operator hosts. Users are advised to upgrade immediately to mitigate the risk.

    0000062
    268 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in jm33-m0 emp3r0r (CVE-2026-26068) https://vuldb.com/?id.345801

    Post summary

    A newly identified high‑severity vulnerability (CVE‑2026‑26068) affecting the jm33‑m0 emp3r0r system has been announced, with reference to a vulnerability database entry.

    0000052
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjm33-m0emp3r0r---

Explore more