SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-60094

MEDIUM · CVSS 6.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Vinchin Backup & Recovery versions up to 9.0.0.86562 are susceptible to a heap buffer overflow vulnerability that can be exploited by unauthenticated remote attackers through specially crafted TCP packets. This flaw may lead to process crashes or memory corruption, posing a risk to system stability and data integrity. Organizations using this software should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-60094
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%

Original NVD Description

Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.