Critical RCE Vulnerability Discovered in SzafirHost Software

Critical RCE Vulnerability Discovered in SzafirHost Software

First seen 29 Jun 2026, 22:43 UTC Mallory.Aicvefeed.iocert.pl 87% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

CERT Polska disclosed CVE-2026-13165, a high-severity remote code execution flaw in Krajowa Izba Rozliczeniowa's SzafirHost software, affecting all versions prior to 1.2.2. The vulnerability stems from inconsistent parsing of signed native library archives, allowing attackers to insert malicious DLL, SO, or DYLIB entries that bypass signature checks. This flaw enables remote code execution when the rogue library is executed from the native temporary directory. The issue was reported by Mariusz Maik and has been fixed in version 1.2.2, released on June 1, 2026. The CVSS score for this vulnerability is 8.6, indicating a significant risk to affected systems. Organizations using SzafirHost are urged to update to the latest version to mitigate this threat.

Key Points: • CVE-2026-13165 is a high-severity RCE vulnerability in SzafirHost software. • Attackers can exploit the flaw by inserting malicious libraries that bypass signature checks. • The vulnerability affects all versions prior to 1.2.2 and has been fixed in the latest release.

ThreatCluster AI

Timeline

2026-06-01
Vulnerability reported to CERT Polska
CERT Polska received a report about a remote code execution flaw in SzafirHost software, leading to coordinated disclosure.
cert.pl
2026-06-01
Patch released for SzafirHost
Krajowa Izba Rozliczeniowa released version 1.2.2 of SzafirHost to address CVE-2026-13165, fixing the RCE vulnerability.
cert.pl
2026-06-29
CVE-2026-13165 published
CERT Polska disclosed CVE-2026-13165, detailing the remote code execution vulnerability in SzafirHost.
Mallory.Ai

Community

Browse all →