CVE-2026-26928General

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The application doesn't verify hash or vendor's digital signature of uploaded DLL, SO, JNILIB or DYLIB file. The attacker can provide malicious file which will be saved in users /temp folder and executed by the application. This issue was fixed in version 1.1.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-02: 1Mentions · 2026-05-25: 1Mentions · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-25: 1Technical Details · 2026-04-02: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-27: 104-0205-2505-27
Signal classification3 categories
General
133.3%
PoC
133.3%
Disclosure
133.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-021
General1
2026-05-251
PoC1
2026-05-271
Disclosure1
Full discourse3 posts
  • ZaufanaTrzeciaStrona @zaufanatrzeciastrona@infosec@Zaufana3Strona
    PoC

    Michał odkrył sposób na logowanie jako dowolny użytkownik do eZUS-u, E-Sądu, eZdrowia i innych rządowych systemów. Poczytajcie, bo to najgrubsze odkrycie tego roku w PL 1. https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/ 2. https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/ 3. https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/ 4. https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/ https://t.co/alwhxevIvH

    Post summary

    Polish post announces a login‑bypass discovery affecting several government systems, citing CVE-2026-26928 and CVE-2026-9058 with linked posts presumably containing proof‑of‑concept details, but no evidence of live exploitation, patches, or mitigation steps.

    211111859039254.3K
    46.0K followersView on X
  • Magdalena A. Tkacz@Magdalen_A_T
    Disclosure

    Zdalne wykonanie kodu w SzafirHost – [CVE-2026-26928] [Badanie e-podpisów, cz. 1] | Zaufana Trzecia Strona https://share.google/VgYYrKlweMbwu7W1r

    Post summary

    The post announces a newly identified remote code execution vulnerability (CVE‑2026‑26928) in SzafirHost, as part of an e‑signature study, but it does not provide exploit details or patch information.

    0000039
    247 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26928 SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified … https://www.cve.org/CVERecord?id=CVE-2026-26928

    Post summary

    The post offers a snapshot of CVE-2026-26928’s behavior without providing any proof of concept, exploit code, patches, or evidence of real‑world exploitation.

    00000108
    56.9K followersView on X

Explore more