
CVE-2026-54161: NUT upsmon: Remote OS command injection via ups.alarm in NOTIFYCMD - fixed in a PR (affects 2.8.3–2.8.5) https://www.openwall.com/lists/oss-security/2026/07/01/10
Post summary
The CVE-2026-54161 vulnerability involves a remote OS command injection in NUT upsmon's NOTIFYCMD configuration. A patch has been released in a PR for versions 2.8.3–2.8.5, and no PoC, exploit code, or active exploitation activity is reported.

