CRITICAL
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection
Published Sep 10, 2026
9.2
CRITICALCVSS 4.0
EPSS 2.33%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.