SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67921

CRITICAL · CVSS 9.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Halo CMS versions up to 2.25.4 are vulnerable to a Cross-Site Request Forgery (CSRF) flaw in the CorsConfigurer.java and CsrfConfigurer.java components, enabling remote attackers to execute arbitrary code. Organizations using affected versions of Halo CMS should prioritize patching this vulnerability to mitigate the risk of unauthorized actions and potential system compromise. Immediate action is recommended for those managing web applications that rely on this content management system.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67921
Severity
CRITICAL
CVSS
9.3
EPSS
0.20%
Java

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.