Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-65639: ConfigServer Security & Firewall lets attacker run commands as root

CVE-2026-65639 · published 1 month ago
Summary

Both the original ConfigServer Security & Firewall and the WebPros-maintained version can let a remote attacker who controls an allow/deny feed run any command with full system privileges. This happens because the software does not properly check the data it receives from the feed. Update to version 16.30 (or later) and review any other custom forks for the same issue.

What to do
  • Update webpros configserver security & firewall to version 16.30 or later.
  • Update configserver configserver security & firewall to version * or later.
Affected software
VendorProductAffected versions
webpros configserver security & firewall < 16.30
configserver configserver security & firewall < *
Original advisory text
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to...
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.

The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.5 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-65639 · MITRE
Track software like this
Free during beta