SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-83772

CRITICAL · CVSS 9.9 EPSS 1.69% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical command injection vulnerability exists in the JSON parsing function of the mail-report.sh script within Cobham SATCOM VSAT7090 Maritime Satellite Router, allowing remote attackers to manipulate sender/recipient arguments. This flaw poses a significant risk as it could lead to unauthorized command execution on affected devices. Organizations using this router should prioritize immediate remediation efforts to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-83772
Severity
CRITICAL
CVSS
9.9
EPSS
1.69%

Original NVD Description

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.