CVE-2026-60094Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-09: 3Technical Details · 2026-07-09: 307-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • frycos@frycos
    Disclosure

    You all know I like backup solution. Some time ago, I looked at Vinchin Backup & Recovery. Most known vulns seemed targeting the web interfaces. My CVE-2026-60094 and CVE-2026-60095 tell a different story: plenty of mem corruptions in other remote services.

    Post summary

    The post briefly discloses that CVE-2026-60094 and CVE-2026-60095 involve memory corruption in remote services of Vinchin Backup & Recovery, without providing proof‑of‑concepts, exploits, or patch information.

    110921.0K
    3.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-60094 Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or mem… https://www.cve.org/CVERecord?id=CVE-2026-60094

    Post summary

    The text announces CVE‑2026‑60094 as a heap buffer overflow that enables unauthenticated remote attackers to crash the process.

    00010752
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-60094 Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or mem… https://www.cve.org/CVERecord?id=CVE-2026-60094 ----- Traducción: CVE-2026-60094 Vin… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑60094, revealing that Vinchin Backup & Recovery v9.0.0.86562 suffers a heap buffer overflow which can be triggered by unauthenticated remote attackers to cause a process crash.

    0000035
    91 followersView on X

Explore more