SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67854

CRITICAL · CVSS 9.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Qcms version 6.0.6 is vulnerable to an SQL Injection flaw that enables remote attackers to execute arbitrary code on the affected system. Organizations using this version of Qcms should prioritize remediation efforts to mitigate potential unauthorized access and control over their databases. Immediate action is recommended for those managing sensitive data or critical applications reliant on this software.

CVE
CVE-2026-67854
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%

Original NVD Description

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code