CVE-2026-3977Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation leads to missing authorization. The attack can be initiated remotely. The identifier of the patch is 35dfd6f08f7d517709c77ee73e57367141107e6b. To fix this issue, it is recommended to deploy a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-12: 3Technical Details · 2026-03-12: 203-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3977 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3977 #CVE-2026-3977 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/u6pABx6Rd1

    Post summary

    The tweet announces a new CVE-2026-3977 with medium severity and unspecified affected products, referencing the NVD for details.

    0000029
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3977 A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of the component AJAX Endpoints. The manipulation lea… https://www.cve.org/CVERecord?id=CVE-2026-3977

    Post summary

    The post announces the detection of CVE‑2026‑3977 in projectsend up to r1945, mentioning a component and an unnamed manipulation, but provides no technical, exploitation, or mitigation details.

    0000095
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3977 - projectsend AJAX Endpoints authorization Intel Report: https://ift.tt/9CRYQqi

    Post summary

    The post alerts users to CVE-2026-3977, noting an authorization bypass on projectsend AJAX endpoints and linking to an intel report, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000088
    342 followersView on X

Explore more