SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67402

CRITICAL · CVSS 9.2 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache installations using ConfigServer Security & Firewall with Messenger v3 in HTTPS mode are vulnerable due to an insecure configuration that allows remote unauthenticated attackers to execute arbitrary commands as the Apache user. This critical vulnerability, rated 9.2 on the CVSS scale, poses a significant risk to system integrity and confidentiality. Administrators of affected systems should prioritize updating to version 16.31 to mitigate this risk.

CVE
CVE-2026-67402
Severity
CRITICAL
CVSS
9.2
EPSS
0.32%
Apache

Original NVD Description

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.