CVE-2026-37347Active Exploitation

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-16); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Mentions · 2026-04-27: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 1Technical Details · 2026-04-27: 104-1604-1704-27
Signal classification3 categories
Active Exploitation
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-162
Active Exploitation1Disclosure1
2026-04-172
Active Exploitation1Disclosure1
2026-04-271
Patch1
Full discourse5 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-37347 | CVSS 9.1 SourceCodester Payroll Management System v1[.]0 vulnerable to SQL Injection in /payroll/view_employee[.]php. Network exploitable, no auth required. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/sqQQFGSBGG

    Post summary

    The tweet highlights a critical SQL injection in SourceCodester Payroll Management System and urges immediate patching to mitigate the risk.

    0000030
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37347 SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. https://www.cve.org/CVERecord?id=CVE-2026-37347

    Post summary

    The text announces a new CVE—CVE-2026-37347—highlighting a SQL Injection vulnerability in SourceCodester Payroll Management and Information System v1.0, with a link to the CVE record for further details.

    0000081
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting SourceCodester Payroll Management and Information System (CVE-2026-37347) https://vuldb.com/vuln/357944/cti

    Post summary

    The tweet reports observed actor activity targeting CVE-2026-37347, indicating possible active exploitation, but provides no PoC, exploit code, patch, or technical specifics.

    0000063
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-37347 SQL Injection in SourceCodester Payroll Management and Informatio... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37347 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    An announcement of CVE-2026-37347, a SQL Injection vulnerability in SourceCodester Payroll Management, with links to vulnerability details and alert customization.

    0000050
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-37347 SourceCodester Payroll Management and Information System v1… CVSS 9.1 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-37347 #HP #CyberSecurity #InfoSec

    Post summary

    CVE‑2026‑37347 is reported as critically vulnerable with exploits already active in the wild, yet no patch is yet available.

    000001
    145 followersView on X

Explore more