CVE-2026-40552General

LOWCVSS 4.7 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Multiple BinSoft products are vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote network resource. Alternatively, it is possible to use a previously uploaded file and change its reference. When the application processes the attachment, and a user tries to open it, the referenced resource is executed by the system. Critically, this vulnerability can be exploited by any unauthenticated attacker by chaining it with CVE-2026-40550 and CVE-2026-40551, which allows obtaining database access, and logging onto any account. The described issue affects all published versions. The vendor stated that this issue is a direct result of the architecture model in which the software is distributed, and that it will be mitigated with a corrected installation manual.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-669

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-04-29: 1Active Exploitation · 2026-04-29: 102-0304-29
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-031
General1
2026-04-291
Active Exploitation1
Full discourse2 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting BinSoft mpGabinet (CVE-2026-40552) https://vuldb.com/vuln/359974/cti

    Post summary

    The post indicates that actors are targeting CVE-2026-40552 in BinSoft mpGabinet, suggesting active exploitation, though it lacks details about the exploit, patch, or technical specifics.

    0101055
    2.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SolarWinds ❗ CVE-2026-40553 ❗ CVE-2026-40552 ❗ CVE-2026-40551 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-solarwinds-2/ https://t.co/8n5ZbLdRdU

    Post summary

    The tweet lists three CVE identifiers for SolarWinds products and directs readers to a CERT website for more information, without providing technical, exploit, or mitigation details.

    00000104
    6.6K followersView on X

Explore more