Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-18808: Klemsan KIO lets attackers run their own code
CVE-2026-18808 · published 2 days ago
Summary
The Klemsan Internet Objects (KIO) software, versions before 1.9, can be tricked into executing code that an attacker supplies. This could let a malicious user take control of the system or steal data. Update to version 1.9 or later as soon as possible to stop the risk.
What to do
- Update klemsan electrical electronics inc. kio (klemsan internet objects) to version v1.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| klemsan electrical electronics inc. | kio (klemsan internet objects) | < v1.9 |
Original advisory text
Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection.
This issue affects KIO (Klemsan Internet Objects): before v1.9.
This issue affects KIO (Klemsan Internet Objects): before v1.9.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta