SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15544

HIGH · CVSS 8.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the getupsvar function of the apcupsd component in Shibby Tomato versions up to 1.28.0000, allowing remote attackers to exploit this flaw. Successful exploitation could lead to arbitrary code execution, posing a significant risk to affected systems. Users and administrators of Shibby Tomato should prioritize patching or migrating to FreshTomato to mitigate potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15544
Severity
HIGH
CVSS
8.8
EPSS
0.44%

Original NVD Description

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.