{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/openfind/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openfind:secushare_pro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-107459"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SecuShare Pro"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","vulnerability","webserver"],"_cs_type":"threat","_cs_vendors":["Openfind"],"content_html":"\u003cp\u003eOpenfind SecuShare Pro contains a critical OS command injection vulnerability, identified as CVE-2026-107459. This vulnerability permits unauthenticated remote attackers to send specially crafted requests to the application, resulting in the execution of arbitrary operating system commands with the privileges of the web service. With a CVSS v3.1 base score of 9.8, this flaw represents a significant risk to organizations using the SecuShare Pro solution, as it enables full system compromise without requiring prior authentication or user interaction. Defenders should prioritize identifying instances of this software within their network and monitoring for abnormal process execution originating from the web server process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full remote code execution on the underlying server hosting SecuShare Pro. This can result in complete system compromise, unauthorized data exfiltration, lateral movement within the network, and the deployment of additional malware or ransomware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing or internal SecuShare Pro instances. Monitor web server logs for suspicious parameter values containing common command injection indicators (e.g., semicolon, pipe, or backtick characters) directed at the application API. Check for unexpected child processes being spawned by the web service process (e.g., cmd.exe, sh, bash) and investigate any suspicious outbound network activity originating from the application server.\u003c/p\u003e\n","date_modified":"2026-10-08T06:50:25Z","date_published":"2026-10-08T06:50:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-secushare-rce/","summary":"Openfind SecuShare Pro is vulnerable to an unauthenticated OS command injection flaw (CVE-2026-107459) allowing remote attackers to execute arbitrary commands on the host server.","title":"Unauthenticated OS Command Injection in Openfind SecuShare Pro","url":"https://feed.craftedsignal.io/briefs/2026-10-secushare-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Openfind","version":"https://jsonfeed.org/version/1.1"}