Our takeCISA flags an OS command injection in ZoneMinder (versions 1.37.48 and 1.38.3) — CVSS 8.8, full RCE as the web server user. This open-source camera software runs in plenty of small shops: update, and if your web interface is reachable from the internet, fix that today.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of CVE-2026-23702 (OS command injection) in ZoneMinder 1.37.48 and 1.38.3, enabling full RCE as the web server user. Update to a fixed release immediately if you run it.
What this means for you — Lean IT orgs:If you run ZoneMinder 1.37.48 or 1.38.3, update it right away — this flaw lets attackers run commands on your server.
What this means for you — MSP:ZoneMinder 1.37.48 and 1.38.3 have a confirmed OS command injection flaw (CVSS 8.8) that CISA says is exploited in the wild, leading to RCE as the web server. Check every client instance and patch or upgrade now.
What this means for you — Researcher:CISA added this OS command injection (improper neutralization of special elements) in ZoneMinder 1.37.48/1.38.3 to its catalog: confirmed exploited, CVSS 8.8, full RCE as web server user.