CVE-2026-41468Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1104

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-23)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-22: 1Mentions · 2026-04-23: 2PoC Mentioned / Linked · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 204-2204-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-232
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41468 Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present… https://www.cve.org/CVERecord?id=CVE-2026-41468

    Post summary

    The text announces CVE‑2026‑41468, noting it involves AngularJS 1.5.2's sandbox escape primitives and template injection, but provides no evidence of exploitation or mitigations.

    00010159
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41468 Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present… https://www.cve.org/CVERecord?id=CVE-2026-41468 ----- Traducción: CVE-2026-41468 Beg… http://infoflow.cloud`

    Post summary

    The text reports CVE‑2026‑41468 affecting Beghelli Sicuro24 SicuroWeb, highlighting that AngularJS 1.5.2 (an end‑of‑life component) contains sandbox escape primitives and template injection issues.

    0000036
    72 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-41468: Beghelli Sicuro24 SicuroWeb Angu... AngularJS 1.5.2 EOL + template injection = game over for Beghelli operators; MITM attackers get full browser RCE via sa... https://zerodaysignal.com/vulnerability/CVE-2026-41468 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2026-41468, a template injection flaw in AngularJS 1.5.2 used by Beghelli, which allows MITM attackers to achieve full browser RCE, with a link for further details.

    00000106
    218 followersView on X

Explore more