CVE-2026-38526Disclosure

CRITICALCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 15 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 18 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 7 mentions (2026-09-12); latest day: 3
  • 29 total mentions across 15 days

Deep dive

Activity timeline29 mentions / 15d
02457Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 3Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-07-14: 1Mentions · 2026-07-17: 1Mentions · 2026-09-12: 7Mentions · 2026-09-15: 1Mentions · 2026-09-16: 2Mentions · 2026-09-30: 4Mentions · 2026-10-01: 3PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-22: 2PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-17: 1PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-16: 1PoC Mentioned / Linked · 2026-09-30: 1Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-09-12: 1Exploit Tool / Code · 2026-09-15: 1Exploit Tool / Code · 2026-09-30: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-22: 3Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 3Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-14: 1Technical Details · 2026-07-17: 1Technical Details · 2026-09-12: 5Technical Details · 2026-09-15: 1Technical Details · 2026-09-30: 104-1504-1704-1804-1904-2104-2206-2506-2607-1407-1709-1209-1509-1609-3010-01
Signal classification5 categories
Disclosure
730.4%
Exploit
730.4%
PoC
626.1%
General
28.7%
Patch
14.3%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-04-151
General1
2026-04-171
PoC1
2026-04-181
Patch1
2026-04-191
Disclosure1
2026-04-211
Disclosure1
2026-04-223
Disclosure2Exploit1
2026-06-251
PoC1
2026-06-261
Exploit1
2026-07-141
PoC1
2026-07-171
PoC1
2026-09-127
Disclosure2Exploit3General1PoC1
2026-09-151
Exploit1
2026-09-162
Disclosure1PoC1
2026-09-304
Exploit1
Full discourse20 posts
  • Dark Web Intelligence@DailyDarkWeb
    Disclosure

    🚨 Critical Vulnerability: CVE-2026-38526 (CVSS 10.0) in Krayin CRM A newly disclosed vulnerability, CVE-2026-38526, affects Krayin CRM and allows authenticated arbitrary file upload, potentially leading to full system compromise. 📊 Key Details: • CVE: CVE-2026-38526 • Severity: CVSS 10.0 (Critical) • Affected: Krayin CRM • Type: Authenticated Arbitrary File Upload 🧠 Exploitation Overview: • Requires authenticated access (low barrier in many environments) • Attacker can upload malicious files (e.g., web shells) • Leads to: Remote Code Execution (RCE) Full server takeover 🧠 Threat Intelligence Insight: • File upload vulnerabilities are highly weaponizable: Common initial access vector Often chained with privilege escalation • Public POC availability significantly increases risk: Lowers barrier for exploitation Enables rapid mass scanning and targeting • Shodan query already shared → indicates: Active targeting / reconnaissance underway ⚠️ Assessment: • High credibility (technical details + POC available) • High exploitation likelihood in short timeframe ⚠️ Potential Impact: • Full compromise of CRM systems • Exposure of customer and business data • Lateral movement within internal networks 📊 Status: Active — patching and mitigation urgently required #CyberSecurity #Vulnerability #CVE #ThreatIntel #RCE #DDW

    Post summary

    Critical CVE-2026-38526 disclosed in Krayin CRM allows authenticated arbitrary file upload leading to RCE; public PoC is available and patching is urgently required.

    16052137.0K
    194.4K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-38526: Krayin CRM RCE Exploit "This PoC exploits the vulnerable TinyMCE upload endpoint (/admin/tinymce/upload) to upload a PHP webshell and achieve command execution on the server." CVSS: 9.9 Published: June 24th, 2026 PoC: https://github.com/pawpic/CVE-2026-38526-POC https://t.co/g6VJ59Th9U

    Post summary

    The tweet announces a proof‑of‑concept for CVE‑2026‑38526, detailing an RCE via the TinyMCE upload endpoint and providing a GitHub link to the PoC code, with a CVSS score of 9.9.

    1100371610.8K
    226.8K followersView on X
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-38526(CVSS 10.0) : An Authenticated Arbitrary File Upload Vulnerability in Krayin CRM. 🔥PoC : https://github.com/TREXNEGRO/Security-Advisories/blob/main/CVE-2026-38526/poc.md https://github.com/TREXNEGRO/Security-Advisories/tree/main/CVE-2026-38526 📊 2.7K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Krayin%20CRM%22 👇Query HUNTER : http://product.name="Krayin CRM" 📰Refer:https://securityonline.info/krayin-crm-rce-vulnerability-cve-2026-38526-fix/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    A CVE‑2026‑38526 authenticated arbitrary file upload vulnerability in Krayin CRM is disclosed with linked PoC code, but no active exploitation or patch details are mentioned.

    111025122.9K
    26.0K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #CVE-2026-38526 #Exploit Kit — #Krayin #CRM #RCE Kit Contents + http://scanner.py # Krayin CRM instance discovery and vulnerability scanner + http://exploit.py # Webshell upload exploit with RCE, reverse shells, file transfer + requirements.txt #Python dependencies + README.md # Detailed analysis #0days #security #hacking #antisec

    Post summary

    The post announces an exploit kit for CVE‑2026‑38526 targeting Krayin CRM, including an upload exploit script that achieves remote code execution and reverse shells, but it does not report active wild exploitation or any patch.

    09026111.3K
    1.8K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit (CVE-2026-38526) PoC: https://github.com/CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526 https://t.co/Yyx7itE0bz

    Post summary

    The post announces a Proof of Concept for an authenticated remote code execution flaw in Krayin CRM v2.2.x (CVE‑2026‑38526) and supplies a GitHub link to the exploit code, with no indications of active exploitation or available patches.

    0902879.1K
    234.5K followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-49869 (CVSS: 10) kestra-io CVE-2026-38526 (CVSS: 9.9) CVE-2021-43716 (CVSS: 9.8) CVE-2021-43717 (CVSS: 9.8) ..🧵👇

    10062554
    374 followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-55182 (CVSS: 10) Meta CVE-2026-100886 (CVSS: 10) Seetong CVE-2026-85706 (CVSS: 10) gitlab CVE-2026-38526 (CVSS: 9.9) CVE-2017-5941 (CVSS: 9.8) ..🧵👇

    10021105
    374 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة CVE-2026-38526 بخطورة CVSS 10 تم اكتشافها في إطار Krayin CRM تم اكتشاف ثغرة أمنية بخطيرة CVSS 10 في إطار Krayin CRM مفتوح المصدر والذي يعتمد على Laravel و Vue.js. تحمل هذه الثغرة رقم CVE-2026-38526 وتعتبر من الثغرات عالية الخطورة. لم يتم الكشف عن تفاصيل تقنية محددة حول كيفية استغلال هذه الثغرة، ولكن يُنصح بضرورة تصحيح الإصدارات المتأثرة على الفور. 🔗 للمزيد: https://securityonline.info/krayin-crm-rce-vulnerability-cve-2026-38526-fix/

    Post summary

    The post announces a high‑severity CVE in Krayin CRM and urges prompt patching, but it offers no exploit details or evidence of active exploitation.

    00040577
    268 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-57819 — FreePBX · PoC live ├ CVE-2026-49869 — Kestra · PoC live ├ CVE-2026-38526 (9.9) · PoC live └ CVE-2021-43716 · CVE-2021-43717 (9.8) · PoC live

    1001051
    374 followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-38526 PT ID: PT-2026-32680 Description: An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. References: • https://dbu.gs/vulnerability/PT-2026-32680 • https://github.com/shirouuu/gitea-template-sync-path-traversal-privilege-escalation-cve-2026-38526-

    Post summary

    Authenticated arbitrary file upload in Webkul Krayin CRM v2.2.x allows code execution via crafted PHP; PoC/exploit code is referenced through a GitHub repository.

    00002738
    3.5K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-38526: ‼️Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit (CVE-2026-38526) PoC: (v2.2) 0day Intel: ‼️Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit (CVE-2026-38526)

    Post summary

    The post announces a newly disclosed authenticated RCE vulnerability (CVE-2026-38526) in Krayin CRM v2.2.x and confirms a PoC is available, but it does not mention active exploitation or mitigation.

    11000131
    325 followersView on X
  • SOCRadar®@socradar
    Exploit

    A simple file upload should not hand over the keys to your server. But with CVE-2026-38526, that is exactly what is happening. 🚨 If you are running Krayin CRM v2.2.x, here is the reality check: 🔹It features an authenticated Remote Code Execution (RCE) vulnerability. The flaw stems from an exposed TinyMCE upload endpoint. 🔹A public Proof of Concept (PoC) is already out in the wild. 🔹Threat actors are actively sharing exploit details and Shodan queries on the dark web. If your admin panel is exposed to the internet, it is time to reduce your risk. Restrict access immediately and mitigate script execution in your upload paths before someone else does the testing for your network. Read more at the link below. 👇 https://hubs.la/Q04d0FNm0 #CyberSecurity #VulnerabilityManagement #RCE #ThreatIntelligence #KrayinCRM

    Post summary

    CVE‑2026‑38526 enables authenticated remote code execution in Krayin CRM v2.2.x via a TinyMCE upload endpoint; a public PoC exists and threat actors are actively exploiting it, so immediate restriction and mitigation are recommended.

    00011299
    5.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-38526 (CVSS 9.9) in Krayin CRM v2.2.x allows authenticated RCE via TinyMCE file upload. PoC circulating on Dark Web with Shodan dork targeting exposed instances. Disable PHP execution in upload directories immediately. #DFIR_Radar https://t.co/nEPz1jMDHq

    Post summary

    The tweet announces CVE‑2026‑38526, a CVSS 9.9 authenticated remote code execution in Krayin CRM via TinyMCE upload. It notes a PoC on the dark web and urges disabling PHP execution in upload directories.

    10010204
    1.7K followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2026-38526 [CRITICAL/PoC] CVSS: 9.9 CVE-2026-38526 🔗 https://exploitgrid.net/exploits/1d9cd18e-1d1f-484b-a032-b548bb0c7ab4

    1000050
    374 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-55182 — Meta/React · "React2Shell" PoC live ├ CVE-2026-100886 — Seetong TS81xx · RCE PoC live ├ CVE-2026-85706 — GitLab · PoC live └ CVE-2026-38526 (9.9) · CVE-2017-5941 (9.8) · PoC live

    10000832
    371 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2026-38526 [CRITICAL/PoC] CVSS: 9.9 CVE-2026-38526 🔗 https://exploitgrid.net/exploits/29e107b3-2d66-427b-bd31-20b728eecef9

    Post summary

    The text highlights a critical vulnerability (CVE-2026-38526) with a CVSS score of 9.9 and shares a link to an exploit, indicating the availability of functional exploit code.

    1000043
    371 followersView on X
  • ExploitGrid@exploitgrid

    15 associated exploits. CVSS 9.9. CVE-2026-38526 affects Webkul Krayin CRM v2.2.x with an authenticated file upload flaw that can lead to arbitrary code execution via a crafted PHP file. Public exploit | EPSS 2.35% ExploitGrid: 48.5/100 Medium 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-38526

    0001081
    371 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] CVE-2026-38526 [CRITICAL/PoC] CVE-2026-38526-KrayinCRM 🔗 https://exploitgrid.net/exploits/214cc132-2599-4584-92c8-f28b2cc58d62

    Post summary

    The post shares a Proof of Concept for CVE-2026-38526 affecting KrayinCRM, providing a link to an exploit on exploitgrid.net. No patch, technical details, or active exploitation claims are mentioned.

    1000053
    45 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-3094 CVE-2025-24813 CVE-2026-48907 CVE-2026-38526 CVE-2024-36401 ..🧵👇

    Post summary

    The tweet is a brief threat digest that lists five CVE numbers labeled as 'Critical Exploits disclosed today' but provides no technical details, exploit tools, PoC links, remediation guidance, or exploitation status—only announcement-level information is present.

    1000071
    45 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    Source: X search for PoC exploit 2026 Posted: 2026-07-14T23:30:04.000Z Likes: 22 0day Intel: ‼️Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit (CVE-2026-38526)

    Post summary

    The tweet announces a 0day Intel about an authenticated remote code execution exploit targeting Krayin CRM v2.2.x (CVE‑2026‑38526), providing vulnerability type details but no PoC, patch, or evidence of active exploitation.

    1000073
    325 followersView on X

Explore more