SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18808

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical code injection vulnerability exists in Klemsan Internet Objects (KIO) versions prior to 1.9, allowing attackers to execute arbitrary code on affected systems. This flaw poses a significant risk to the integrity and confidentiality of the system, making it essential for organizations using KIO to prioritize immediate updates to mitigate potential exploitation. Users of KIO should assess their deployments and apply the necessary patches without delay.

CVE
CVE-2026-18808
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.