CVE-2026-39906General(unisys / webperfect_image_suite)

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques. Attackers can capture the leaked NTLMv2 hash and relay it to other hosts to achieve privilege escalation or lateral movement depending on network configuration and patch level.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webperfect_image_suite

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
webperfect_image_suite

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-15: 2Mentions · 2026-05-12: 2Technical Details · 2026-04-15: 1Technical Details · 2026-05-12: 104-1505-12
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1General1
2026-05-122
General2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CRITICAL: CVE-2026-39906 (CVSS 10) — unisys webperfect image suite

    Post summary

    The post simply announces a critical CVE (CVE-2026-39906) with CVSS score 10 for the UniSys WebPerfect Image Suite, without providing forensic details or mitigation advice.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-39906-unisys-webperfect-image-suite #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely references a CVE URL and relevant hashtags but provides no specific information about the vulnerability, its exploitation, or mitigation.

    0000021
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39906 Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to… https://www.cve.org/CVERecord?id=CVE-2026-39906

    Post summary

    Announces CVE‑2026‑39906, highlighting a remote unauthenticated vulnerability in Unisys WebPerfect Image Suite caused by a deprecated .NET Remoting channel.

    0000092
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39906 Remote NTLMv2 Hash Leakage in Unisys WebPerfect Image Suite 3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39906 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post simply announces the existence of CVE-2026-39906 with a link to a notification, but provides no additional technical, exploit, or mitigation details.

    0000051
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appunisyswebperfect_image_suite3.0.3960.22604--
Appunisyswebperfect_image_suite3.0.3960.22810--

Explore more