CVE-2026-17561
CRITICAL · 9.8CRITICAL rating + confirmed RCE attack vector, but no KEV listing, no public PoC yet, patch status unclear.
What: Code injection vulnerability in Innotim Software Logsign SIEM (<6.4.108) enabling unauthenticated remote code execution; CVSS 9.8 CRITICAL.
Why it matters: Published 31 July 2026 with CRITICAL severity and strong social signal on patch urgency. No KEV listing yet, and patch status remains unclear despite vendor advisory. Defenders are actively discussing containment and monitoring. High CVSS + confirmed RCE attack vector drives immediate triage priority.
Where it's seen: Bluesky chatter across infosec community, threat radar aggregators, and news feeds (HackerWire, OffSeq Radar). Posts emphasize unauthenticated RCE, lack of confirmed patch, and mitigation guidance (access restriction, monitoring).
RISK: CRITICAL — Unauthenticated RCE, CVSS 9.8, active vendor advisory, no patch confirmation yet.
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High