CRITICAL
9.8 CVE-2026-63722 Published 19 Aug 2026
ICEcoder 8.1 Remote Code Execution Bug
Worried this affects one of your servers?
ICEcoder 8.1 contains a serious vulnerability that allows unauthenticated attackers to execute arbitrary OS commands.
Attackers can exploit this by sending a specially crafted HTTP POST request to the terminal endpoint, bypassing authentication and CSRF validation, and executing commands as the web-server user.
Reference: CVE-2026-63722 on NVD
← Back to Security News