Redpacketsecurity Critical Vulnerabilities in SxDevOps Expose Remote Code Execution Risks
Article Content
- •Three critical CVEs disclosed for SxDevOps with CVSS scores up to 9.8.
- •Vulnerabilities allow remote code execution and exploitation of hardcoded credentials.
- •Patches are available; immediate application is recommended for affected systems.
On September 20, 2026, multiple critical vulnerabilities were disclosed in SxDevOps versions 1.0 and 1.1, including CVE-2026-93970, CVE-2026-93969, and CVE-2026-93971. These vulnerabilities allow for remote code execution (RCE) and the exploitation of hardcoded credentials, posing significant risks to organizations using the software. The vulnerabilities were identified in various components, including the settings and RBAC services, with a CVSS score of up to 9.8 for certain issues. Attackers can exploit these flaws without user interaction, making internet-facing deployments particularly vulnerable. The vendor has released patches for these vulnerabilities, and organizations are urged to apply them immediately. The absence of confirmed exploitation does not diminish the urgency for remediation, especially for systems exposed to the internet. Security teams should review logs for unauthorized access and rotate any potentially compromised credentials.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track CVE-2026-33413 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed