logo

Zoneminder

ID: be8c6d46-1da3-5cff-a11b-914494928992

STIX ID: report--be8c6d46-1da3-5cff-a11b-914494928992

Feed Name: CISA Advisories

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: CISA

...
...

CISA published an advisory for Zoneminder describing an OS command injection vulnerability (CVSS v3 8.8) in versions 1.37.48 and 1.38.3 that could allow full remote code execution as the web server user; a public proof-of-concept was discovered and reported, and CISA provides mitigation recommendations and defensive best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.