CVE-2026-108546
Published 10 October 2026 · tracked since 11 October 2026
Description
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substitute
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105892 CRITICAL 9.8
- CVE-2026-62044 HIGH 7.2
- CVE-2026-104398 CRITICAL 9.8
- CVE-2026-94676 HIGH 7.2
- CVE-2026-105885 HIGH 8.8
- CVE-2026-108162 MEDIUM 6.5
- CVE-2026-108164 MEDIUM 6.5
- CVE-2026-91136 HIGH 7.5
- CVE-2026-96662 HIGH 7.5
- CVE-2026-93945 CRITICAL 9.8