CVE-2026-47782Active Exploitation

MEDIUMCVSS 4.6 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-357

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-21: 1Active Exploitation · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-25: 105-2105-25
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-211
Active Exploitation1
2026-05-251
Disclosure1
Full discourse2 posts
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    権限チェックの抜け、intentの検証漏れ、教員PC1台からNASまでの侵入、そしてAIが自分で脆弱性を見つけ始めた日。今日のニュースは『小さな前提の抜け』が連鎖で破滅に化ける話だ。 ・Movable Type CVE-2026-44392、権限チェック欠如で意図せぬアップデートが走る ・RoboForm Android CVE-2026-47782、intent検証不備で無警告ファイル取得 ・東北大学、教員PC起点で大学病院NASまで侵入、治験データ漏えいの恐れ ・Instructure Canvas、ShinyHuntersに2億7500万件流出、教育分野で過去最大 ・Cloudflare、AnthropicのMythosで脆弱性発見からPoC生成まで自律実行を検証 AIが自分で脆弱性を見つけてPoCまで作る時代だ。みんなの現場は、まだ『パッチが出てから動く』そのままで通用するか?権限の境界、もう一度引き直す時期じゃないか?

    Post summary

    The post highlights multiple CVEs, notes that AI can autonomously generate PoCs, and reports that real‑world intrusions have reached university infrastructure, indicating ongoing exploitation challenges.

    00070411
    1.2K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【RoboForm AndroidにIntent検証不備の脆弱性】 JVNは、RoboForm AndroidにIntent URLの検証不備に起因する脆弱性 CVE-2026-47782 が存在すると公表しました。 影響を受けるのはAndroid版RoboForm 9.8.6.3以前で、悪意あるアプリからのIntentにより、ユーザー通知なしにファイルをダウンロードさせられる可能性があります。 深刻度は高くないものの、パスワード管理アプリに関わる点は軽視できません。特にBYODや業務用Android端末では、利用アプリの把握と更新確認が重要です。 日本の組織では、端末管理ポリシー、業務利用を許可しているパスワード管理アプリ、野良アプリのインストール制御を見直したい情報です。 #RoboForm #Android #CVE202647782 #JVN #モバイルセキュリティ #パスワード管理 #BYOD https://jvn.jp/vu/JVNVU93461473/

    Post summary

    JVN announced the CVE‑2026‑47782 vulnerability in RoboForm Android, detailing an Intent URL validation flaw that could let malicious apps download files without user consent, but no exploit code, patch, or evidence of active exploitation is referenced.

    00010253
    3.7K followersView on X

Explore more