CVE-2026-37749Disclosure

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-17); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-17: 2Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1Active Exploitation · 2026-04-17: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 104-1704-1804-19
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-172
Active Exploitation1General1
2026-04-182
Disclosure2
2026-04-191
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-37749 A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username … https://www.cve.org/CVERecord?id=CVE-2026-37749

    Post summary

    The text announces a new SQL injection flaw (CVE-2026-37749) in CodeAstro Simple Attendance Management System v1.0 that permits unauthenticated remote attackers to bypass authentication.

    00000114
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40342 | CVSS 9.9 🔴 CVE-2026-40351 | CVSS 9.8 🔴 CVE-2026-37749 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post simply lists three newly disclosed CVEs along with their high CVSS scores, without providing any further technical details, exploit code, patches, or evidence of active exploitation.

    0000081
    5.6K followersView on X
  • Varad_PM@varad_mene
    Disclosure

    How I Found My First CVE — SQL Injection Authentication Bypass (CVE-2026-37749) https://medium.com/@menevarad007/how-i-found-my-first-cve-sql-injection-authentication-bypass-cve-2026-37749-e13d6f82caec

    Post summary

    The Medium article announces the author’s first discovery of CVE‑2026‑37749, describing it as a SQL injection that bypasses authentication.

    0000075
    50 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Active Exploitation

    🚨 CRITICAL — CVE-2026-37749 A SQL injection vulnerability in CodeAstro Simple Attendanc… CVSS 9.8 ⚡ Exploit in the wild 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-37749 #Tenda #CyberSecurity #InfoSec

    Post summary

    CVE-2026-37749 is a critical SQL injection vulnerability with a CVSS score of 9.8 that is actively exploited in the wild, but no patch has yet been released.

    000002
    145 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-37749 CVE-2026-37749 CVE-2026-37749 — CodeAstro Simple Attendance Manag... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37749 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post simply lists CVE‑2026‑37749 and links to a Vulmon vulnerability page, providing no additional details on exploitation, patches, or technical aspects.

    0000049
    4.0K followersView on X

Explore more