SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79035

MEDIUM · CVSS 6.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in the p.rfihub.com component of the Zeta Marketing Platform (ZMP) v1.0 allows for reflected cross-site scripting (XSS), enabling attackers to execute arbitrary JavaScript in the victim's browser by injecting a malicious URL into the ca parameter. Organizations utilizing this version of ZMP should prioritize remediation efforts to mitigate potential exploitation that could lead to unauthorized access or data theft. Security teams should assess their exposure and implement necessary patches or workarounds promptly.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79035
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%
Java

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.