CVE-2026-39440General

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-08-27)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-23: 1Mentions · 2026-08-27: 3PoC Mentioned / Linked · 2026-08-27: 2Exploit Tool / Code · 2026-08-27: 2Patch / Workaround · 2026-08-27: 1Technical Details · 2026-04-23: 104-2308-27
Signal classification3 categories
General
250.0%
Exploit
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-231
General1
2026-08-273
Exploit1General1PoC1
Full discourse4 posts
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-86Ijgy7 [CRITICAL/PoC] Linked: CVE-2026-39440 cve-2026-39440-funnelforms-fix 🔗 https://exploitgrid.net/exploits/c9edfe25-c278-4c2b-8925-3d34976965f7

    Post summary

    The post announces a PoC and exploit code for CVE‑2026‑39440 with a link to an exploit page and a reference to a fix, but it does not provide technical details or evidence of active exploitation.

    1000037
    38 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-86Ijgy7 [CRITICAL/PoC] Linked: CVE-2026-39440 cve-2026-39440-funnelforms-fix 🔗 https://exploitgrid.net/exploits/c9edfe25-c278-4c2b-8925-3d34976965f7

    Post summary

    A critical PoC/exploit for CVE‑2026‑39440 is provided via a link to ExploitGrid, indicating the availability of a functional exploit code.

    1000040
    38 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-39440 CVE-2026-24118 CVE-2023-20887 CVE-2023-20887 CVE-2023-20887 ..🧵👇

    Post summary

    The post lists several critical CVE identifiers with no additional information on exploits, POCs, or remediation.

    1000040
    38 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39440 Improper Control of Generation of Code ('Code Injection') vulnerability ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39440 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new code injection vulnerability (CVE-2026-39440) is announced with basic title and links to detailed info, but no PoC, exploit, or patch details are included.

    0000047
    4.0K followersView on X

Explore more