Unrated severityNVD Advisory· Published Jan 20, 2026· Updated Jan 21, 2026
CVE-2026-21640
CVE-2026-21640
Description
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.
Affected products
2- Revive/Revive Adserverv5Range: 6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.