CVE & Vulnerabilities · September 6, 2026
A newly disclosed flaw tracked as CVE-2026-67402 affects ConfigServer Security & Firewall's Messenger v3 component, whose HTTPS virtual host is misconfigured to expose system binaries as executable CGI scripts. That misconfiguration lets a blocked, unauthenticated attacker trigger arbitrary commands running under the web server's own account. WebPros has already shipped a fix in CSF version 16.31, so administrators running Messenger v3 over HTTPS should update without delay.
// source: nvd.nist.gov ↗