SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-41939

CRITICAL · CVSS 9.8 EPSS 0.80% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Care Everywhere Gateway 14.3.10 on Windows contains a critical vulnerability due to hard-coded credentials in the WildFly management interface, allowing unauthenticated remote attackers to gain administrative access. This flaw enables attackers to deploy malicious applications, leading to potential remote code execution with the privileges of the Windows machine account. Organizations still using version 14.x.x, which has been end-of-life since 2017, should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41939
Severity
CRITICAL
CVSS
9.8
EPSS
0.80%
Windows

Original NVD Description

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.