Medium severity6.5NVD Advisory· Published May 1, 2026· Updated May 7, 2026
CVE-2026-26461
CVE-2026-26461
Description
A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
33- In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App FlawsSecurityWeek · May 15, 2026
- AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem?The Register Security · May 13, 2026
- Mystery Microsoft bug leaker keeps the zero-days comingThe Register Security · May 13, 2026
- Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · May 12, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- HEIDI: Free IDE security plugin for open-source vulnerability checksHelp Net Security · May 12, 2026
- Dirty Frag: Linux kernel hit by second major security flaw in two weeksThe Record · May 11, 2026
- Zara Data Breach Impacts Nearly 200,000 CustomersInfosecurity Magazine · May 11, 2026
- Taiwan's train cyber-trauma reveals a global system that's coming off the tracksThe Register Security · May 11, 2026
- In Other News: Train Hacker Arrested, PamDOORa Linux Backdoor, New CISA Director FrontrunnerSecurityWeek · May 8, 2026
- ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New StoriesThe Hacker News · May 7, 2026
- From Stuxnet to ChatGPT: 20 News Events That Shaped CyberDark Reading · May 6, 2026
- TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03), (Mon, May 4th)SANS Internet Storm Center · May 4, 2026
- Blend Autopilot MCP brings AI agent orchestration to lending platformsHelp Net Security · May 4, 2026
- Your work apps are quietly handing 19 data points to someoneHelp Net Security · May 4, 2026
- In Other News: Scattered Spider Hacker Arrested, SOC Effectiveness Metrics, NSA Tool VulnerabilitySecurityWeek · May 1, 2026
- NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years LaterDark Reading · Apr 28, 2026
- TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)SANS Internet Storm Center · Apr 27, 2026
- Widely Used Browser Extensions Selling User DataInfosecurity Magazine · Apr 27, 2026
- As the NVD scales back CVE enrichment, here’s what Tenable customers need to knowTenable Blog · Apr 27, 2026
- Glasswing Secured the Code. The Rest of Your Stack Is Still on YouDark Reading · Apr 24, 2026
- LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of DisclosureThe Hacker News · Apr 24, 2026
- Five steps to become Mythos readyTenable Blog · Apr 23, 2026
- AI is Changing Vulnerability Discovery and your Software Supply Chain Strategy has to Change with itRapid7 Blog · Apr 23, 2026
- ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News · Apr 23, 2026
- Project Glasswing and the Next Challenge for Defenders: Turning Faster Discovery into Faster ActionRapid7 Blog · Apr 20, 2026
- NCSC Outlines Coordinated Plan to Boost NHS Cyber ResilienceInfosecurity Magazine · Apr 20, 2026
- Systemic Flaw in MCP Protocol Could Expose 150 Million DownloadsInfosecurity Magazine · Apr 16, 2026
- AI Companies to Play Bigger Role in CVE Program, Says CISAInfosecurity Magazine · Apr 15, 2026
- Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent VulnerabilitiesCisco Talos Intelligence · Apr 14, 2026
- Just Three Ransomware Gangs Accounted for 40% of Attacks Last MonthInfosecurity Magazine · Apr 10, 2026
- OpenAI Expands Bug Bounty to Cover AI Abuse and 'Safety' ConcernsInfosecurity Magazine · Mar 26, 2026
- Virtual machines, virtually everywhere – and with real security gapsESET WeLiveSecurity · Mar 25, 2026