Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-16097: Shibby Tomato Scheduler Name Handler stack overflow risk

CVE-2026-16097 CVE-2026-16097
Summary

The Shibby Tomato 1.28 Scheduler Name Handler has a vulnerability that could allow an attacker to overflow the system's memory, potentially leading to system crashes or unauthorized access. This issue is especially concerning because it can be exploited remotely, giving an attacker more flexibility. If you're using Shibby Tomato, consider updating to the more recent FreshTomato alternative, which is likely to be more secure.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
shibby tomato 1.28
Original title
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-bas...
Original description
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026