TopVuln

High-risk vulnerability digests

CVE-2026-32968

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-03-23 12:16:08
Affected versions
All versions of systems running the vulnerable com_mb24sysapi module
Summary
This is an unauthenticated remote code execution vulnerability caused by improper neutralization of operating system command special characters. It is a functional variant of the older CVE-2020-10383 vulnerability. Successful exploitation allows attackers to take full control of the affected system.
Remediation
Update the com_mb24sysapi module to the latest patched version released by the vendor. Block unauthenticated external access to endpoints exposing the vulnerable module to reduce attack surface.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.