Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-67854: Qcms v.6.0.6: Remote Code Execution via SQL Injection
CVE-2026-67854 · published 17 days ago
Summary
A security weakness in Qcms v.6.0.6 allows an attacker to run malicious code on the system, potentially leading to data theft or system compromise. To protect your system, update Qcms to the latest version as soon as possible. If you're unable to update, consider using a web application firewall to prevent unauthorized access.
Original advisory text
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta