SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16097

HIGH · CVSS 8.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in the Scheduler Name Handler of Shibby Tomato 1.28 allows remote attackers to manipulate arguments and potentially execute arbitrary code. Users of this firmware, particularly those still utilizing Shibby Tomato, should prioritize patching or migrating to FreshTomato to mitigate the risk of exploitation. Given the high severity rating, immediate action is recommended for all affected users.

CVE
CVE-2026-16097
Severity
HIGH
CVSS
8.8
EPSS
0.46%

Original NVD Description

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.