Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-65638: ConfigServer Security & Firewall lets remote attacker run commands
CVE-2026-65638 · published 1 month ago
Summary
A flaw in ConfigServer Security & Firewall lets anyone on the internet send a specially crafted request that runs commands on the server using the firewall’s own account. This can give an attacker control over the system. Update to version 16.30 or verify that any other versions you use have been patched.
What to do
- Update webpros configserver security & firewall to version 16.30 or later.
- Update configserver configserver security & firewall to version * or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | configserver security & firewall | < 16.30 |
| configserver | configserver security & firewall | < * |
Original advisory text
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injectio...
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-78OS Command Injection
Timeline
Published10 Sep 2026
Updated8 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta