CVE-2026-60095Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-09: 3Technical Details · 2026-07-09: 307-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • frycos@frycos
    Disclosure

    You all know I like backup solution. Some time ago, I looked at Vinchin Backup & Recovery. Most known vulns seemed targeting the web interfaces. My CVE-2026-60094 and CVE-2026-60095 tell a different story: plenty of mem corruptions in other remote services.

    Post summary

    The post announces that CVE-2026-60094 and CVE-2026-60095 expose memory corruption vulnerabilities in remote services of Vinchin Backup & Recovery, contrasting with typical web‑interface attacks.

    110921.0K
    3.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-60095 Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allo… https://www.cve.org/CVERecord?id=CVE-2026-60095

    Post summary

    The CVE-2026-60095 announcement exposes a stack buffer overflow in Vinchin Backup & Recovery’s ModuleHandShake function, with no evidence of exploitation or patch details.

    00010750
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-60095 Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allo… https://www.cve.org/CVERecord?id=CVE-2026-60095 ----- Traducción: CVE-2026-60095 Vin… http://infoflow.cloud`

    Post summary

    The message announces CVE‑2026‑60095, identifies it as a stack buffer overflow in the agentlink_server service, and links to the official CVE record, but provides no indication of exploitation, mitigation, or PoC availability.

    0000035
    91 followersView on X

Explore more