Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107459 2026-10-08

Openfind SecuShare Pro OS Command Injection (CVE-2026-107459) Allows Unauthenticated Remote Code Execution

"CVE-2026-107459 is a critical OS command injection flaw in Openfind's SecuShare Pro. Unauthenticated remote attackers can use it to run arbitrary operating system commands on the server."

CVE-2026-107459 is a critical OS command injection flaw in Openfind's SecuShare Pro. Unauthenticated remote attackers can use it to run arbitrary operating system commands on the server.

What Is It

CVE-2026-107459 is an OS Command Injection vulnerability (CWE-78) in SecuShare Pro, developed by Openfind. The NVD record says unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

TWCERT/CC ([email protected]) reported the flaw. NVD published the record on 2026-10-08, and its status is "Received." NVD has not yet completed its own analysis.

Why It Matters

The flaw carries a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The CVSS v4.0 score is 9.3 (CRITICAL).

The scoring describes the worst-case profile for a server-side bug:

Any attacker who can reach a vulnerable SecuShare Pro instance over the network could potentially take full control of the server's command execution context, without credentials or any action by a user.

Exploitation status: The supplied CISA KEV data contains no entry for this CVE, so CISA has not confirmed active exploitation in the source material. The CVSS v4.0 Exploit Maturity metric is also "Not Defined." Lack of KEV listing does not mean the flaw is not being exploited, and the severity profile justifies treating it as a priority.

What's Vulnerable

Vendor Product Affected Version
Openfind SecuShare Pro 4

The record's default status for other versions is "unaffected." NVD has not yet published any CPE configurations.

Patch Status

The supplied NVD record includes no patched version numbers or vendor remediation steps. Because there is no KEV entry, there is also no CISA required action or due date.

Organizations running SecuShare Pro version 4 should:

Sources