Mallory.Ai Critical RCE Vulnerability Discovered in SzafirHost Software
Article Content
- •CVE-2026-13165 is a high-severity RCE vulnerability in SzafirHost software.
- •Attackers can exploit the flaw by inserting malicious libraries that bypass signature checks.
- •The vulnerability affects all versions prior to 1.2.2 and has been fixed in the latest release.
CERT Polska disclosed CVE-2026-13165, a high-severity remote code execution flaw in Krajowa Izba Rozliczeniowa's SzafirHost software, affecting all versions prior to 1.2.2. The vulnerability stems from inconsistent parsing of signed native library archives, allowing attackers to insert malicious DLL, SO, or DYLIB entries that bypass signature checks. This flaw enables remote code execution when the rogue library is executed from the native temporary directory. The issue was reported by Mariusz Maik and has been fixed in version 1.2.2, released on June 1, 2026. The CVSS score for this vulnerability is 8.6, indicating a significant risk to affected systems. Organizations using SzafirHost are urged to update to the latest version to mitigate this threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CERT Polska and CVE-2026-13165 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…