
🚨High - Revive Adserver Code Injection Bypass (CVE-2026-50741) CVE-2026-50741 is a bypass to the previous fix for CVE-2026-34916 in Revive Adserver. An authenticated low-privileged user can still inject malicious PHP code into the delivery limitations by sending a disallowed but valid plugin identifier as the type parameter or by using the ox.setChannelTargeting XML-RPC API method. This allows arbitrary PHP code execution during banner delivery. 👉Affected: Revive Adserver (versions affected by the incomplete fix for CVE-2026-34916) Action: Update to the latest patched version of Revive Adserver.
Post summary
The advisory discloses CVE-2026‑50741, details how it bypasses a prior patch, and recommends applying the latest patched version of Revive Adserver.



