CVE-2026-32968Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (6 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-23: 6PoC Mentioned / Linked · 2026-03-23: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 503-23
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-32968 — CVSS 9.8/10 ██████████ Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/CoIzby5WW9

    Post summary

    CVE‑2026‑32968 is a critical, remote command‑injection vulnerability (CVSS 9.8/10) for which a patch is currently available, as announced in the tweet.

    1000028
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32968 Remote Code Execution in Com_mb24sysapi Module via Command Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32968

    Post summary

    The post announces a remote code execution vulnerability (CVE-2026-32968) caused by command injection in the Com_mb24sysapi module and points to a reference page.

    0000046
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32968 - Critical Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting i... https://www.thehackerwire.com/vulnerability/CVE-2026-32968/ https://t.co/KyMdN8R0do

    Post summary

    The tweet announces a critical RCE vulnerability (CVE-2026-32968) in com_mb24sysapi caused by unsafe command string handling, providing technical details but no PoC, exploit code, patch, or active exploitation claims.

    0000045
    144 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for MB connect line mbCONNECT24 and mymbCONNECT24 (CVE-2026-32968) https://vuldb.com/?id.352502

    Post summary

    The post announces the discovery of CVE‑2026‑32968 for MB CONNECT24 and mymbCONNECT24, noting that its severity has increased, but it provides no technical details, exploit code, or mitigation information.

    0000053
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32968: CRITICAL] Unauthenticated remote attackers can exploit RCE vulnerability in com_mb24sysapi module due to improper OS command neutralization, leading to system compromise. Variant of CVE-2020...#cve,CVE-2026-32968,#cybersecurity https://cvefind.com/CVE-2026-32968

    Post summary

    The text is a straightforward disclosure of CVE-2026-32968, describing a critical remote code execution flaw in the com_mb24sysapi module caused by improper command neutralization.

    0000067
    605 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32968: Unauthenticated RCE in com_mb24s... Another MB connect line OS injection drops with zero auth required - industrial IoT devices serving shells to anyone wh... https://zerodaysignal.com/vulnerability/CVE-2026-32968 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-32968, an unauthenticated remote code execution vulnerability in MB connect line industrial IoT devices, and links to an external site for further details.

    0000048
    162 followersView on X

Explore more