Vulnerabilities in ConfigServer
3 resultsVexday analysis
ConfigServer apresenta perfil de risco baixo com apenas 1 vulnerabilidade crítica registrada na base, sem evidência de exploração ativa em campo. A fraqueza identificada (CWE-552 - permissões inadequadas) foi divulgada recentemente, demandando atenção imediata para aplicação de patches, mas o volume reduzido de exposições históricas sugere superfície de ataque limitada.
CVE-2026-65638CRITICALImproper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commaEPSS 3.2%CVE-2026-65639CRITICALOS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured alloEPSS 1.6%CVE-2026-67402CRITICALAn insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual hoEPSS 0.3%