CVE-2026-15544
published 2026-07-13CVE-2026-15544: A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component…
PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.79%
54.8th percentile
A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apcupsd | apcupsd | <= 3.14.14 | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
| shibby | tomato | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
ghsa_unreviewed·2026-09-30·CVSS 8.8
CVE-2026-103432 [HIGH] CWE-121 apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
GHSA
A vulnerability was determined in Shibby Tomato up to 1.28.0000.
ghsa_unreviewed·2026-07-13
CVE-2026-15544 [HIGH] CWE-119 A vulnerability was determined in Shibby Tomato up to 1.28.0000.
A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
VulDB
Shibby Tomato up to 1.28.0000 apcupsd tomatodata.cgi getupsvar Field stack-based overflow (IJTQ5M)
vuldb·2026-07-12
CVE-2026-15544 [CRITICAL] Shibby Tomato up to 1.28.0000 apcupsd tomatodata.cgi getupsvar Field stack-based overflow (IJTQ5M)
A vulnerability was found in Shibby Tomato up to 1.28.0000. It has been classified as critical. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes stack-based buffer overflow.
This vulnerability appears as CVE-2026-15544. The attack may be initiated remotely. In addition, an exploit is available.
This project is superseded by FreshTomato.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [epel-all]
bugzilla·2026-09-30·CVSS 8.1
CVE-2026-103432 [HIGH] CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [epel-all]
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
Bugzilla
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar
bugzilla·2026-09-30·CVSS 8.1
CVE-2026-103432 [HIGH] CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
Bugzilla
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [fedora-all]
bugzilla·2026-09-30·CVSS 8.1
CVE-2026-103432 [HIGH] CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [fedora-all]
CVE-2026-103432 apcupsd: apcupsd: Arbitrary code execution via stack-based buffer overflow in getupsvar [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
2026-07-13
Published