Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-26787

AI Predicted 9.8 Difficulty: Trivial EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-26787

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initial startup of the container sets a property of "allowany" to allow any user with a valid and trusted client auth certificate to connect. Admins can then set more restricted access to specific certificates. A logic error caused this admin CLI command to be run on each restart of the container instead of only the first startup as intended resetting the configuration to "allowany".
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Keyfactor SignServer 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Keyfactor SignServer是美国Keyfactor公司的一个数字签名引擎。 Keyfactor SignServer 7.2之前版本存在安全漏洞,该漏洞源于容器启动逻辑错误,可能导致重置配置为allowany。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-26787

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-26787

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-12-22 · 27 CVEs total

CVE-2025-150046.3 MEDIUMDedeCMS freelist_main.php sql injection
CVE-2025-150053.7 LOWCouchCMS reCAPTCHA config.example.php hard-coded key
CVE-2025-65857Xiongmai XM530 安全漏洞
CVE-2025-67436PluXml 安全漏洞
CVE-2025-65856Xiongmai XM530 安全漏洞
CVE-2025-66736youlai-boot 安全漏洞
CVE-2025-66735youlai-boot 安全漏洞
CVE-2025-65817LSC Smart Connect Indoor IP Camera 安全漏洞
CVE-2024-27708AIRC MyNET 安全漏洞
CVE-2025-67291Piranha CMS 安全漏洞
CVE-2025-67290Piranha CMS 安全漏洞
CVE-2025-65837PublicCMS 安全漏洞
CVE-2025-65790Real Time Logic FuguHub 安全漏洞
CVE-2025-67418ClipBucket 安全漏洞
CVE-2024-25812AIRC MyNET 安全漏洞
CVE-2024-35321AIRC MyNET 安全漏洞
CVE-2024-25814AIRC MyNET 安全漏洞
CVE-2025-67288Umbraco CMS 安全漏洞
CVE-2025-63662GT Edge AI 安全漏洞
CVE-2025-63664GT Edge AI 安全漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-26787

No comments yet


Leave a comment