Zoneminder

Summary

A critical OS Command Injection vulnerability (CVE-2026-76060) has been identified in specific versions of ZoneMinder (1.37.48 and 1.38.3). Successful exploitation by an authenticated user could lead to full Remote Code Execution (RCE) on the server.

IFF Assessment

FOE

This vulnerability allows attackers to execute arbitrary commands on the server, posing a direct threat to system integrity and data security.

Severity

8.8 High

Defender Context

This vulnerability affects ZoneMinder, a popular video surveillance software often used in critical infrastructure. Defenders should prioritize patching affected systems to version 1.38.3 or later immediately. Monitoring for unusual command execution patterns from ZoneMinder's web server process is also recommended.

Read Full Story →