CRITICAL
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data
Published Sep 10, 2026
9.5
CRITICALCVSS 4.0
EPSS 1.42%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.