www.brinztech.com Critical Command Injection Vulnerability in Cobham SATCOM Routers
Article Content
- •CVE-2026-83772 allows remote command execution on Cobham SATCOM VSAT7090 routers.
- •Exploit code is publicly available, increasing the risk of attacks on maritime operations.
- •Immediate isolation of management interfaces and firmware updates are recommended.
A critical command-injection vulnerability, tracked as CVE-2026-83772, has been disclosed in Cobham SATCOM VSAT7090 satellite communication routers, affecting maritime fleets globally. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the router's operating system due to improper input handling in the JSON Parsing component. The vulnerability poses severe risks, including traffic interception, total communication blackouts, and potential access to onboard networks. Weaponized exploit code is already circulating, increasing the urgency for mitigation. Maritime operators are advised to isolate management interfaces and apply vendor firmware updates immediately. A patch is available for affected systems, specifically versions up to 20260704. The CVSS score assigned to this vulnerability is 9.9, indicating its critical nature. The situation is evolving, and organizations must act swiftly to protect their infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Mirage Kitten, Cobham Satcom and CVE-2026-62911 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…