AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19035

HIGH · CVSS 7.2 EPSS 2.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the new_qoslimit_start function of Shibby Tomato 1.28.0000, allowing remote attackers to execute arbitrary OS commands by manipulating the new_qoslimit_enable argument. Organizations still using this version of Shibby Tomato should prioritize patching or migrating to FreshTomato, as the exploit is publicly available and poses a significant security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19035
Severity
HIGH
CVSS
7.2
EPSS
2.47%

Original NVD Description

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.