CVE-2026-35507Disclosure(shynet / shynet)

LOWCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for shynet shynet systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Shynet before 0.14.0 allows Host header injection in the password reset flow.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shynet

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-03); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
shynet

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-03: 2Mentions · 2026-06-18: 1Active Exploitation · 2026-06-18: 1Technical Details · 2026-04-03: 2Technical Details · 2026-06-18: 104-0306-18
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure2
2026-06-181
Active Exploitation1
Full discourse3 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2026-35507 to manipulate Shynet password reset flows via Host header injection. The vulnerability enabled credential theft by redirecting users to attacker-controlled domains. Runtime segmentation helps contain such post-compromise lateral movement across cloud environments. #Vulnerability :link: Full breakdown: https://aviatrix.ai/threat-research-center/shynet-vulnerability-cve-2026-35507

    Post summary

    Attackers have leveraged a Host header injection flaw in Shynet’s password reset flow (CVE-2026-35507) to redirect users and steal credentials, with details further expanded in an external article.

    0000044
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35507 Shynet before 0.14.0 allows Host header injection in the password reset flow. https://www.cve.org/CVERecord?id=CVE-2026-35507

    Post summary

    The post announces a Host header injection vulnerability in Shynet’s password reset functionality, highlighting the affected version range.

    0000081
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-35507 📊 Severity: 6.4 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-35507 #CVE-2026-35507 #CVE #Medium #CyberSecurity #InfoSec https://t.co/N033eVFdXP

    Post summary

    The tweet announces CVE‑2026‑35507, noting a CVSS score of 6.4 and a medium risk level, but offers no further technical details, exploitation evidence, or mitigation information.

    0000037
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshynetshynet---

Explore more