CVE-2025-26776
CVSS 3.1 Score 10 of 10 (high)
Details
Published Feb 22, 2025
CWE ID 434
Summary
CVE-2025-26776 is a critical vulnerability affecting the NotFound Chaty Pro software. Hackers can exploit this Unrestricted File Upload vulnerability to upload a web shell to a web server, gaining unauthorized access and control. This issue poses a serious threat as it allows attackers to bypass access restrictions and execute malicious code. The vulnerability affects versions of Chaty Pro from n/a through 3.3.3. Immediate steps should be taken to update and patch affected systems to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share