CRITICAL 9.8 CVE-2026-63722 Published 19 Aug 2026

ICEcoder 8.1 Remote Code Execution Bug

Worried this affects one of your servers?

ICEcoder 8.1 contains a serious vulnerability that allows unauthenticated attackers to execute arbitrary OS commands.

Attackers can exploit this by sending a specially crafted HTTP POST request to the terminal endpoint, bypassing authentication and CSRF validation, and executing commands as the web-server user.

Reference: CVE-2026-63722 on NVD

← Back to Security News