CVE-2026-26335Disclosure(calero / verasmart)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch calero verasmart systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacker who obtains these keys can craft a valid ASP.NET ViewState payload that passes integrity validation and is accepted by the application, resulting in server-side deserialization and remote code execution in the context of the IIS application.

4.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-321

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • verasmart

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-14)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
verasmart

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-13: 1Mentions · 2026-02-14: 3PoC Mentioned / Linked · 2026-02-14: 1Exploit Tool / Code · 2026-02-14: 1Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 302-1302-14
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
PoC
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-131
Disclosure1
2026-02-143
Disclosure1Patch1PoC1
Full discourse4 posts
  • Clandestine@akaclandestine
    PoC

    GitHub - mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE https://github.com/mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE

    Post summary

    A GitHub repository provides a proof‑of‑concept exploit for CVE‑2026‑26335, a remote code execution flaw in Calero VeraSMART, but there is no evidence of active exploitation or patch information.

    030841.1K
    54.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26335 Calero VeraSMART versions prior to 2022 R1 use static http://ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)… https://www.cve.org/CVERecord?id=CVE-2026-26335

    Post summary

    The advisory explains that earlier VeraSMART versions use hard‑coded ASP.NET/IIS machineKey values stored locally, increasing the potential risk of exploitation.

    00020246
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26335 Remote Code Execution in Calero VeraSMART via Insecure http://ASP.NET ViewState Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26335

    Post summary

    CVE-2026-26335 reveals a remote code execution vulnerability in Calero VeraSMART caused by insecure ASP.NET ViewState deserialization, with no indication of active exploitation or available fixes.

    0000059
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-26335 hits Calero VeraSMART (pre-2022 R1) — hard-coded crypto keys allow unauth RCE! Update now or rotate keys for protection. European orgs at risk. Details: https://radar.offseq.com/threat/cve-2026-26335-cwe-321-use-of-hard-coded-cryptogra-07023d75 #OffS... https://t.co/vgb96gESYL

    Post summary

    The tweet announces the critical CVE-2026-26335, highlights an unauthenticated RCE via hard‑coded keys, and urges immediate updates or key rotation for mitigation.

    0000064
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appcaleroverasmart---
Appcaleroverasmart2022.0--

Explore more