Back Redpacketsecurity CVE Alert: CVE-2026-92980 – danielbrendel – hortusfox
HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can leverage the Import/Export feature, which is intended solely for data portability, to deploy and execute malicious code on the underlying application server host.
High risk: prioritise remediation promptly, although no KEV, active SSVC exploitation, EPSS, or PoC status is supplied to confirm exploitation urgency.
Successful abuse can give an attacker control of the application account’s server context, enabling data theft, tampering, service disruption, persistence, or use of the host to attack other internal systems. The main business risk is compromise of a trusted management application and any sensitive information or credentials accessible from its host.
### Most likely attack path
The path is network-based, requires low attacker effort and no victim interaction, but depends on a previously compromised or otherwise obtained administrator account. Because Scope is unchanged, direct impact is centred on the application host; lateral movement remains possible through harvested credentials, reachable internal services, or shared infrastructure.
### Who is most exposed
Internet-facing, self-hosted deployments are most exposed, particularly instances administered by several users, running in containers with broad filesystem access, or hosted alongside other internal services.
Review import/export activity, especially unusual archive types, frequency, or source addresses.
Alert on web-server child processes spawning shells, interpreters, or download utilities.
Hunt for recently created executable files in upload, temporary, and application directories.
Correlate administrator logins with subsequent outbound connections or configuration changes.
### Mitigation and prioritisation
Upgrade to the vendor-fixed release as soon as change controls permit; treat as high-priority remediation.
If KEV is later confirmed or EPSS is at least 0.5, treat as priority 1.
Restrict administrative access through VPN, allow-lists, and MFA where supported.
Disable or tightly restrict import/export until patched, after testing operational dependencies.
Rotate application and host credentials if suspicious activity or exploitation is identified.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
