SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-65639

CRITICAL · CVSS 9.5 EPSS 1.61%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A critical OS command injection vulnerability exists in the advanced-rule parser of ConfigServer Security & Firewall, allowing remote attackers to execute arbitrary commands as root due to inadequate validation of rule data from configured allow/deny feeds. This issue impacts both the original ConfigServer versions and the WebPros-maintained fork, with a fix provided in version 16.30. Organizations using affected versions, especially those managing firewall configurations, should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-65639
Severity
CRITICAL
CVSS
9.5
EPSS
1.61%

Original NVD Description

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.