logo

Critical Unauthenticated RCE in HGiga OAKlouds via Insecure Deserialization (CVE-2026-93467)

ID: 420115bd-429b-50bc-a83f-a76b4f1c7c1b

STIX ID: report--420115bd-429b-50bc-a83f-a76b4f1c7c1b

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-09-18

Date Updated: 2026-09-19

...
...

A critical unauthenticated insecure deserialization vulnerability (CVE-2026-93467) in HGiga OAKlouds (OAKlouds-custom_page 2.0) allows remote code execution (CVSS 9.8) without credentials or user interaction; no patched version is published yet. The advisory details the attack flow, impact (full server compromise and data exfiltration), immediate mitigations (restrict network exposure, deploy WAF, monitoring) and detection indicators, and notes a related arbitrary file read vulnerability (CVE-2026-93468).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.