Skip to content

CVE-2026-108860

CVE

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
October 11, 2026
Last Seen
October 11, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical OS command injection vulnerability, CVE-2026-108540, has been identified in OpenSpug Spug versions up to 4.0.1, allowing remote attackers to execute arbitrary OS commands. This flaw affects the file transfer functionality (/exec/transfer) and requires low privileges for exploitation. Affe...

Public Exploits

Checking GitHub for proof-of-concept code…