CVE-2026-29781PoC(bishopfox / sliver)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for bishopfox sliver systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure "kill-switch," instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations. At time of publication, there are no publicly available patches.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sliver

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
sliver

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-18: 1Exploit Tool / Code · 2026-03-05: 103-0503-0703-18
Signal classification3 categories
PoC
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
PoC1
2026-03-071
General1
2026-03-181
Disclosure1
Full discourse3 posts
  • skove@skoveit
    Disclosure

    🚨 2 Zero-Days in Sliver C2 (CVE-2026-29781 | CVE-2026-32941) https://skoveit.github.io/skoving/writeups/C2/Sliver-UnoReverse/

    Post summary

    The post announces two zero‑day vulnerabilities in Sliver’s C2 system (CVE‑2026‑29781 and CVE‑2026‑32941) and directs readers to a writeup that presumably contains further details.

    04071514
    18 followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - skoveit/CVE-2026-29781: CVE-2026-29781 PoC - uno reverse · GitHub - https://github.com/skoveit/CVE-2026-29781?tab=readme-ov-file

    Post summary

    A GitHub repository containing a Proof of Concept for CVE-2026-29781 is referenced, but no evidence of active exploitation, patch, or detailed vulnerability information is provided.

    01032647
    5.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29781 Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Pr… https://www.cve.org/CVERecord?id=CVE-2026-29781

    Post summary

    The post announces the existence of a vulnerability in older Sliver C2 server versions, but provides no detailed technical or exploitation information.

    00010143
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbishopfoxsliver---

Explore more