CVE-2026-59800Patch

MEDIUMCVSS 9.2 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to the stdin of a 'sudo -S sh' child process. When sudo does not prompt for a password (the process runs as root, NOPASSWD is configured, or a recent sudo timestamp cache exists), the sudoPassword value is interpreted by sh as a shell command, allowing a remote unauthenticated attacker to execute arbitrary OS commands. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-07-04 (UTC).

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-12: 1Active Exploitation · 2026-07-12: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-12: 107-0707-12
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Classification over time
DateTotalLabels
2026-07-071
Patch1
2026-07-121
Active Exploitation1
Full discourse2 posts
  • つみかさね@tsumikasanedev
    Active Exploitation

    認証不要でコマンド実行が可能 — 9Router(CVE-2026-59800, CVSS9.8)はShadowserverが実際の攻撃を確認。PleskにもCVSS9.9の重大情報漏洩が公開。

    Post summary

    The post confirms CVE-2026-59800 is being exploited in the wild, enabling unauthenticated command execution on 9Router, and also highlights a severe Plesk information‑leak vulnerability.

    10000144
    2 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-59800 — CVSS 9.8/10 ██████████ 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/2XS6laqaCt

    Post summary

    The tweet discloses a critical OS command injection (CVE‑2026‑59800) in 9Router versions before 0.4.44, highlights its high CVSS score, and urges users to apply the available patch.

    1000075
    64 followersView on X

Explore more