CVE-2026-71368Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-20)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-17: 1Mentions · 2026-08-20: 2Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-20: 208-1708-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-171
Disclosure1
2026-08-202
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-71368 F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performe… https://www.cve.org/CVERecord?id=CVE-2026-71368

    Post summary

    The post announces a new XSS flaw (CVE-2026‑71368) in F‑RevoCRM, detailing the attack vector but offering no proof‑of‑concept, exploit, patch, or evidence of current exploitation.

    01011695
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-71368 F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performe… https://www.cve.org/CVERecord?id=CVE-2026-71368 ----- Traducción: CVE-2026-71368 F-R… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑71368, a cross‑site scripting vulnerability in F‑RevoCRM that could allow unintended operations when users view crafted pages while logged in.

    0000023
    102 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 🌐 Vulnerability · August 17, 2026 🎯 New F-RevoCRM XSS vulnerability disclosed — CVE-2026-71368 Japan Vulnerability Notes has disclosed a cross-site scripting vulnerability affecting F-RevoCRM versions 7.3.0 through 8.0.3. Tracked as CVE-2026-71368, the flaw carries a CVSS v3 score of 6.1. According to JVN, a logged-in user who accesses a specially crafted page could be induced into performing unintended actions. Users are advised to upgrade to the latest available release. 🔗 Source: JVN / JPCERT/CC / IPA #CVE202671368 #XSS #CRM #AppSec #CyberSecurity #Vulnerability #PatchManagement

    Post summary

    A cross‑site scripting vulnerability (CVE‑2026‑71368) affecting F‑RevoCRM versions 7.3.0–8.0.3 has been disclosed with a CVSS score of 6.1, and users are urged to upgrade to the latest release.

    0000029
    72 followersView on X

Explore more