SEPTEMBER 29, 2026
Live Feed
Back to database
Case File

CVE-2026-6721

CRITICAL · CVSS 9.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-09-29

CyberRota Analysis

AI-Generated

IBM Concert versions 1.0.0 through 3.0.0 are vulnerable to unauthenticated remote command execution due to improper handling of specially crafted input. This critical flaw allows attackers to execute arbitrary commands on the underlying system with the application's privileges, potentially leading to full system compromise. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-6721
Severity
CRITICAL
CVSS
9.8
EPSS
N/A

Original NVD Description

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)