<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>HortusFox - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/hortusfox/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 17:59:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/hortusfox/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in HortusFox-Web via Import/Export</title><link>https://feed.craftedsignal.io/briefs/2026-09-hortusfox-rce/</link><pubDate>Thu, 17 Sep 2026 17:59:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-hortusfox-rce/</guid><description>HortusFox-Web versions prior to 6.1 are vulnerable to remote code execution allowing authenticated administrators to execute arbitrary OS commands via the Import/Export feature.</description><content:encoded><![CDATA[<p>HortusFox-Web versions prior to 6.1 contain a remote code execution vulnerability (CVE-2026-92980) that allows authenticated administrators to execute arbitrary OS commands on the underlying host. The vulnerability resides in the application's Import/Export functionality, which is designed for data portability. By injecting malicious payloads into the Import/Export workflow, an authenticated attacker can achieve arbitrary code execution running under the privileges of the web server process. This vulnerability is critical for organizations deploying HortusFox-Web, as it grants full command execution capabilities to any user with administrative access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to execute arbitrary OS commands as the web server user. This could lead to full system compromise of the application server, unauthorized data access, lateral movement within the environment, and persistence mechanism deployment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and remediation teams:</p>
<ul>
<li>Update HortusFox-Web to version 6.1 or later immediately to mitigate CVE-2026-92980.</li>
<li>Audit administrative access logs for the HortusFox-Web application to identify unauthorized or anomalous usage of the Import/Export feature.</li>
<li>Restrict access to the administrative interface of the application to only authorized personnel and secure networks.</li>
<li>Monitor for suspicious child processes spawning from the web server service account (e.g., cmd.exe, /bin/bash) which may indicate exploitation of this vulnerability.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>