CVE-2026-4845General

LOWCVSS 2.1 · LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-07-28: 1Active Exploitation · 2026-07-28: 103-2607-28
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-261
General1
2026-07-281
Active Exploitation1
Full discourse2 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting dameng100 muucmf (CVE-2026-4845) https://vuldb.com/vuln/353150/cti

    Post summary

    CTI analysts report that the CVE-2026-4845 vulnerability in dameng100 muucmf is being actively targeted in the wild, but no PoC, patch, or detailed technical data are disclosed.

    0000070
    2.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4845 A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search… https://www.cve.org/CVERecord?id=CVE-2026-4845

    Post summary

    The entry announces the discovery of CVE-2026-4845 in dameng100 muucmf but provides minimal technical or actionable details.

    0000093
    56.8K followersView on X

Explore more