CVE-2026-56413Patch

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-01); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-10: 107-0107-10
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-011
Patch1
2026-07-101
Disclosure1
Full discourse2 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🎯 StoneFly Storage Concentrator: Perfect 10, Perfect Storm Two CVSSv3 10.0 vulnerabilities in StoneFly's Storage Concentrator (SC and SCVM) lead the pack this week. CVE-2026-56413 is a command injection flaw in the ms_service.pl service…

    Post summary

    The text announces two CVSS 10.0 command injection vulnerabilities in StoneFly Storage Concentrator, specifically CVE-2026-56413, with no PoC, exploit, patch, or active exploitation details provided.

    1000032
    85 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🪨 StoneFly Storage Concentrator has a CVSS 10 command injection flaw (CVE-2026-56413) — no auth needed, exposed on TCP port 9000. Full RCE remotely. CISA ICS advisory is out. Patch immediately. #ICS #Cybersecurity https://secalerts.co/vulnerability/CVE-2026-56413?utm_campaign=x https://t.co/jKtYcQMavr

    Post summary

    StoneFly Storage Concentrator is vulnerable to a CVSS 10 command injection flaw enabling full remote code execution without authentication; a CISA advisory has been issued and an immediate patch is recommended.

    00000127
    847 followersView on X

Explore more