CVE-2026-88558

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-15: 109-15
Referenced assets1 URL
By indicator
Full discourse1 post
  • Exploit-Garbage@RemotelyFreely

    First CVE IDs are in — MITRE assigned 10 CVEs to our research (CVE-2026-88557 → 88566). All 10 were found, verified end-to-end, and disclosed first by our AI-driven research pipeline. Every single one ships a full root-cause analysis and a working, reproducible PoC — public since day one, no embargoes, no hoarding: CVE-2026-88557 / CVE-2026-88558 — NoMachine Terminal Server 10.0.57 (CVSS 9.8 ×2) Pre-auth heap corruption and stack overflow in the nxwebrunner parsePOST handler. One multipart POST, no credentials: chunk-metadata smash, double-free, and a 1032-byte sprintf overflow overwriting the return address in a non-PIE, canary-less CGI. CVE-2026-88560 — Minuteman UPS Network Management Card 1.60.3 (9.8) Unauthenticated system_param.csp handler concatenates POST fields into root shell commands. UPS/PDU infrastructure, no auth gate. CVE-2026-88562 / CVE-2026-88561 — Lantronix EDS3000PR 3.2.0.0R2 (8.8 ×2) FsUnmount bitmask gap, plus the SSL import and diagnostics handlers building openssl / ping / traceroute commands from unsanitized input — both to root. CVE-2026-88563 — DrayTek Vigor 2960 v1.5.1.6 (8.8) uploadlangs filename passes the HTML-only cgiEscape into system() → root. CVE-2026-88564 — GeoVision GV-TBL4700 V1.06 (8.8) SNMPv3 auth/privacy keys land in a net-snmp-config shell command as root. The same vendor sanitizes this in other models. CVE-2026-88565 — ZesleCP 3.1.21 (8.8) Unrestricted file write in the root-run file-manager save-file path → /etc/cron.d → root within 60 seconds. CVE-2026-88566 — ITRS OP5 Monitor 9.20 (8.8) A patch bypass of CVE-2025-34115: the vendor's fix gates the dangerous-character check behind a permission the default admins group never holds, so it ships OFF. The "fixed" command injection still executes. CVE-2026-88559 — Codologic Codoforum v5.4.1 (7.2) Category-image upload validated only by getimagesize(), attacker filename used verbatim → polyglot PHP webshell. 9 of these came from a single batch, across 8 vendors. Remote-access gateways, UPS infrastructure, industrial device servers, SMB edge routers, surveillance, hosting panels, web forums, IT monitoring. Full writeups + PoCs: https://0day-rubbish.com/blog #CVE #0day #RCE #infosec #cybersecurity #NoMachine #Lantronix #DrayTek #ITRS

    00101162
    126 followersView on X

Explore more