OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-39117

CRITICAL · CVSS 9.8 EPSS 0.75%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical vulnerability in AltumCode 66Uptime versions prior to 54.0.0 and the 66Uptime ping-servers plugin before version 2.0.0 enables remote attackers to execute arbitrary code through the index.php file. This poses a significant risk to systems running these affected versions, potentially leading to unauthorized access and control. Organizations utilizing these products should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-39117
Severity
CRITICAL
CVSS
9.8
EPSS
0.75%

Original NVD Description

An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php