{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/hortusfox/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hortusfox:hortusfox-web:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-92980"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HortusFox-Web (\u003c 6.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["HortusFox"],"content_html":"\u003cp\u003eHortusFox-Web versions prior to 6.1 contain a remote code execution vulnerability (CVE-2026-92980) that allows authenticated administrators to execute arbitrary OS commands on the underlying host. The vulnerability resides in the application's Import/Export functionality, which is designed for data portability. By injecting malicious payloads into the Import/Export workflow, an authenticated attacker can achieve arbitrary code execution running under the privileges of the web server process. This vulnerability is critical for organizations deploying HortusFox-Web, as it grants full command execution capabilities to any user with administrative access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary OS commands as the web server user. This could lead to full system compromise of the application server, unauthorized data access, lateral movement within the environment, and persistence mechanism deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate HortusFox-Web to version 6.1 or later immediately to mitigate CVE-2026-92980.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs for the HortusFox-Web application to identify unauthorized or anomalous usage of the Import/Export feature.\u003c/li\u003e\n\u003cli\u003eRestrict access to the administrative interface of the application to only authorized personnel and secure networks.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious child processes spawning from the web server service account (e.g., cmd.exe, /bin/bash) which may indicate exploitation of this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:59:20Z","date_published":"2026-09-17T17:59:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hortusfox-rce/","summary":"HortusFox-Web versions prior to 6.1 are vulnerable to remote code execution allowing authenticated administrators to execute arbitrary OS commands via the Import/Export feature.","title":"Remote Code Execution in HortusFox-Web via Import/Export","url":"https://feed.craftedsignal.io/briefs/2026-09-hortusfox-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - HortusFox","version":"https://jsonfeed.org/version/1.1"}