CVE-2026-33277Disclosure(jpcert / logontracer)

MEDIUMCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (7 mentions)

Immediate actions

  • Patch jpcert logontracer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • logontracer

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked at 7 mentions on most recent observed day (2026-05-23)
  • 11 total mentions across 3 days

Affected systems

Vendors
Products
logontracer

Deep dive

Activity timeline11 mentions / 3d
02457Mentions · 2026-04-27: 3Mentions · 2026-04-30: 1Mentions · 2026-05-23: 7Active Exploitation · 2026-05-23: 3Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-30: 1Technical Details · 2026-05-23: 704-2704-3005-23
Signal classification4 categories
Disclosure
654.5%
Active Exploitation
327.3%
General
19.1%
Patch
19.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure2General1
2026-04-301
Patch1
2026-05-237
Active Exploitation3Disclosure4
Full discourse11 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    33277, a — The Defender''s Weapon Becomes the Attack Surface: LogonTracer RCE (CVE-2026-33277) Puts Windows Incident Response at Risk. The Defender's Weapon Becomes the Attack Surface: LogonTracer RCE Now in the Wild

    Post summary

    CVE-2026-33277 is a remote code execution vulnerability in LogonTracer, reportedly being exploited in the wild and threatening Windows incident response.

    1001050
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On April 23, 2026, the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) disclosed CVE-2026-33277, an OS command injection vulnerability in LogonTracer versions prior to v2.0.0. LogonTracer is a freely available tool designed to help security teams…

    Post summary

    JPCERT/CC disclosed CVE‑2026‑33277, an OS command injection flaw affecting LogonTracer versions before 2.0.0.

    1000052
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Japan's CERT (JPCERT/CC) disclosed CVE-2026-33277, a critical OS command injection flaw in LogonTracer, the widely-used open-source tool for investigating malicious Windows logons. Authenticated users can execute arbitrary OS commands with full system privileges (CVSS…

    Post summary

    Japan's CERT discloses CVE-2026-33277, a critical OS command injection flaw in LogonTracer that allows authenticated users to run arbitrary commands with full system privileges.

    1000051
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What this means for your agents and systems: Japan's CERT (JPCERT/CC) disclosed CVE-2026-33277, a critical OS command injection flaw in LogonTracer, the widely-used open-source tool for investigating malicious Windows logons. Authenticated users can execute arbitrary OS…

    Post summary

    Japan's CERT disclosed CVE-2026-33277 as a critical OS command injection flaw in LogonTracer, allowing authenticated users to execute arbitrary OS commands.

    1000050
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Japan's CERT (JPCERT/CC) disclosed CVE-2026-33277, a critical OS command injection flaw in LogonTracer, the widely-used open-source tool for investigating malicious Windows logons. Authenticated users can execute arbitrary OS commands with full system privileges (CVSS…

    Post summary

    Japan's CERT announced CVE-2026-33277, a critical OS command injection vulnerability in LogonTracer that lets authenticated users execute arbitrary commands with full system privileges.

    1000041
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    The Defender's Weapon Becomes the Attack Surface: LogonTracer RCE Now in the Wild Japan's CERT JPCERT/CC disclosed CVE-2026-33277, a critical OS command injection flaw in LogonTracer, the widely-used open-source tool for investigating malicious Windows logons.

    Post summary

    Japan's CERT JPCERT/CC reports a critical OS command injection flaw in LogonTracer, with the headline indicating the vulnerability is being actively exploited in the wild.

    1000049
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-33277 · 8.8 → v2.0.0 The Defender's Weapon Becomes the Attack Surface: LogonTracer RCE Now in the Wild

    Post summary

    CVE-2026-33277 is a LogonTracer RCE that is currently being exploited; the vulnerability is severe (CVSS 8.8) but no mitigations or PoC are provided.

    1000045
    227 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-33277 (CVSS 8.8) OS Command Injection in LogonTracer <v2[.]0[.]0 allows authenticated users to execute arbitrary commands. Upgrade to v2[.]0[.]0+ immediately. #CVE #Vulnerability #PatchNow https://t.co/6KlqsEXjPt

    Post summary

    The tweet alerts that CVE-2026-33277 is a high-severity OS command injection in LogonTracer, and it urges users to upgrade to version 2.0.0 or later for a patch.

    0000031
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33277 An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. https://www.cve.org/CVERecord?id=CVE-2026-33277

    Post summary

    CVE‑2026‑33277 is an OS command injection flaw in LogonTracer that permits arbitrary command execution by a logged‑in user, with no proof‑of‑concept, exploit tool, active exploitation, or patch details provided.

    00000136
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33277 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33277 #CVE-2026-33277 #CVE #High #CyberSecurity #InfoSec https://t.co/qssP7BtRaF

    Post summary

    A new CVE (CVE-2026-33277) with severity 8.8 and high risk level is announced, impacting multiple unspecified products, but no technical details, exploit code, or mitigation information are provided.

    0000048
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33277 OS Command Injection in LogonTracer Prior to Version 2.0.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33277 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-33277, an OS command injection vulnerability in LogonTracer versions prior to 2.0.0, with a link to the vulnerability details.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjpcertlogontracer---

Explore more