CVE-2026-53521Active Exploitation

LOWCVSS 6.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS worker resolves the stored ID and dispatches an update using the other user's DDNS profile configuration in the context of the attacker's server. This issue has been patched in version 2.1.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-06-14: 1Mentions · 2026-06-27: 1Active Exploitation · 2026-03-28: 1Technical Details · 2026-06-14: 1Technical Details · 2026-06-27: 103-2806-1406-27
Signal classification3 categories
Active Exploitation
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-281
Active Exploitation1
2026-06-141
General1
2026-06-271
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-53521 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accept… https://www.cve.org/CVERecord?id=CVE-2026-53521

    Post summary

    The post announces CVE-2026‑53521 affecting Nezha Monitoring between versions 2.0.14 and 2.1.0, lists a vulnerable PATCH /server/{id} endpoint, and provides no exploit or patch details.

    01011162
    57.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Nezha Monitoring, Second-Order Authorization Bypass, #CVE-2026-53521 (Medium) -DC-Jun2026-724 https://dailycve.com/nezha-monitoring-second-order-authorization-bypass-cve-2026-53521-medium-dc-jun2026-724/

    Post summary

    The post announces CVE-2026-53521, a medium‑severity Second‑Order Authorization Bypass in Nezha Monitoring, without mentioning patches, exploits, or active use.

    0000047
    216 followersView on X
  • Ape Manor@apemanor
    Active Exploitation

    📰 CISA Flags CVE-2026-53521 as Critical Threat Amid F5 BIG-IP Exploits The U. What do you think? 💭 👉 https://apemanor.com/article/ac631072-9f70-425f-a1ea-f6d341763f71 #Tech #News #Discussion https://t.co/dgHspFRt1e

    Post summary

    The tweet cites a CISA advisory labeling CVE‑2026‑53521 a critical threat amid F5 BIG‑IP exploits, but it offers no PoC, code, patch, or detailed technical information.

    0000029
    54 followersView on X

Explore more