VYPR

ConfigServer Security & Firewall

by WebPros

CVEs (2)

  • CVE-2026-65639CriSep 10, 2026
    risk 0.62cvss epss

    OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects…

  • CVE-2026-65638CriSep 10, 2026
    risk 0.60cvss epss

    Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by…