High-Risk Vulnerabilities Discovered in ICEcoder

High-Risk Vulnerabilities Discovered in ICEcoder

First seen 10 Sep 2026, 16:01 UTC Redpacketsecuritygithub.com 64.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities (CVE-2026-64836 and CVE-2026-64837) have been identified in ICEcoder versions through 8.1. CVE-2026-64836 allows authenticated attackers to exploit a path traversal vulnerability, enabling unauthorized file access and manipulation. CVE-2026-64837 permits command injection through unescaped filesystem paths, allowing attackers to execute arbitrary commands. Both vulnerabilities pose significant risks to internet-facing installations, particularly in shared hosting environments. Current assessments indicate no active exploitation has been confirmed, but urgent remediation is recommended. The vulnerabilities were published on 2026-09-10, and no mitigation details or proof-of-concept indicators were provided. Affected users are advised to upgrade to fixed releases and restrict access to sensitive functionalities.

Key Points: • CVE-2026-64836 allows path traversal, risking unauthorized file access. • CVE-2026-64837 enables command injection, potentially leading to full server control. • Both vulnerabilities require prompt remediation despite no active exploitation reported.

Ask AI about this cluster

Timeline

2026-09-10
CVE-2026-64836 published
ICEcoder versions through 8.1 contain a path traversal vulnerability due to a logic error, allowing unauthorized file access.
Redpacketsecurity
2026-09-10
CVE-2026-64837 published
ICEcoder through 8.1 passes unescaped filesystem paths to shell commands, enabling command injection.
Redpacketsecurity