CVE-2026-43641

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-22: 109-22
Referenced assets1 URL
Full discourse1 post
  • Anthony Bahn@HoustonIntrove1

    Virtualizor just turned a billing login skip into root. CVE-2026-43641. No password if 4084/4085 face the internet. Builds through 3.2.9 patch 8 are done. Get to patch 9 or 3.3.0 tonight. https://www.vulncheck.com/blog/virtualizor-billing-hook-unauthenticated-root-rce

    0000028
    30 followersView on X

Explore more