Critical RCE Vulnerability Discovered in SzafirHost Software
ID: 249fe7dc-b55d-5571-b3c1-aa1bbe802824
STIX ID: report--249fe7dc-b55d-5571-b3c1-aa1bbe802824
Feed Name: ThreatCluster
Threat Score
CERT Polska disclosed CVE-2026-13165, a high-severity RCE in SzafirHost (affecting all versions prior to 1.2.2) where inconsistent parsing of signed native library archives permits insertion of malicious DLL/SO/DYLIB entries that bypass signature checks and can be executed from the native temporary directory; the issue is fixed in SzafirHost 1.2.2 (released 2026-06-01) and organizations are urged to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
