CVE-2026-27476Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-20)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-19: 2Mentions · 2026-02-20: 3Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 302-1902-20
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-203
Disclosure2Patch1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27476: CRITICAL] Beware: RustFly 2.0.0 vulnerable to command injection via remote UI on UDP port 5005. Attackers can execute system commands using crafted payloads. #CyberSecurity#cve,CVE-2026-27476,#cybersecurity https://cvefind.com/CVE-2026-27476

    Post summary

    RustFly 2.0.0 is affected by a critical command injection vulnerability on UDP port 5005, allowing attackers to execute arbitrary system commands via crafted payloads.

    0000042
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27476 RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sa… https://www.cve.org/CVERecord?id=CVE-2026-27476

    Post summary

    A command injection vulnerability affecting the remote UI control of RustFly 2.0.0 was disclosed, with details of how it can be triggered via UDP.

    00000117
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: OS command injection in Bixat RustFly 2.0.0 (CVE-2026-27476) lets attackers execute system commands remotely via UDP port 5005. Block port 5005 & monitor for threats now! https://radar.offseq.com/threat/cve-2026-27476-improper-neutralization-of-special--c7ddf948 #O... https://t.co/EFU0jWuIgG

    Post summary

    A critical OS command injection vulnerability in Bixat RustFly 2.0.0 via UDP port 5005 has been disclosed, with a recommended mitigation of blocking the port to reduce risk.

    0000030
    265 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-27476 avslöjar en allvarlig kommandoinjektionssårbarhet i RustFly 2.0.0. Oseriösa aktörer kan utnyttja detta för att ta kontroll över system. Viktigt att agera snabbt! #säkerhet #cybersäkerhet #CVE

    Post summary

    The text announces CVE-2026-27476, a critical command injection flaw in RustFly 2.0.0, warns that malicious actors can exploit it to gain system control, and urges prompt action.

    0000038
    7 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27476** pertains to a command injection flaw in **RustFly 2.0.0**, a software application that includes a remote UI control mechanism. The vulnerability arises because the application accepts hex-encoded instructions over UDP port 5005 **without proper sanitization**. Attackers can exploit this flaw by sending crafted payloads containing malicious system commands, leading to arbitrary command execution on the target system. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27476

    Post summary

    The entry discloses a command‑injection vulnerability (CVE-2026-27476) in RustFly 2.0.0 that allows arbitrary command execution via crafted UDP payloads, but provides no patches, PoCs, or evidence of active exploitation.

    0000043
    20 followersView on X

Explore more