logo

Critical RCE Vulnerability Discovered in SzafirHost Software

ID: 249fe7dc-b55d-5571-b3c1-aa1bbe802824

STIX ID: report--249fe7dc-b55d-5571-b3c1-aa1bbe802824

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-29

Date Updated: 2026-07-02

...
...

CERT Polska disclosed CVE-2026-13165, a high-severity RCE in SzafirHost (affecting all versions prior to 1.2.2) where inconsistent parsing of signed native library archives permits insertion of malicious DLL/SO/DYLIB entries that bypass signature checks and can be executed from the native temporary directory; the issue is fixed in SzafirHost 1.2.2 (released 2026-06-01) and organizations are urged to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.