Uncontrolled path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.
Uncontrolled path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.
Active exploitation of CVE-2026-56437 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the 30 days.
CVE-2026-56437 has a CVSS v3 base score of 7.8 (HIGH severity), with vector string 3.0.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
