CVE-2026-2009
published 2026-02-06CVE-2026-2009: A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.25%
16.8th percentile
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mayurik | gas_agency_management_system | — | — |
| sourcecodester | gas_agency_management_system | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cisa8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p967-c764-24hr: A flaw has been found in SourceCodester Gas Agency Management System 1
ghsa_unreviewed·2026-02-06
CVE-2026-2009 [MEDIUM] CWE-266 GHSA-p967-c764-24hr: A flaw has been found in SourceCodester Gas Agency Management System 1
A flaw has been found in SourceCodester Gas Agency Management System 1.0. This issue affects some unknown processing of the file /gasmark/php_action/createUser.php. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been published and may be used.
CISA
Microsoft DirectX NULL Byte Overwrite Vulnerability
cisa·2026-05-20·CVSS 8.8
CVE-2009-1537 [HIGH] Microsoft DirectX NULL Byte Overwrite Vulnerability
Vulnerability: Microsoft DirectX NULL Byte Overwrite Vulnerability
Affected: Microsoft DirectX
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537
Remediation Due Date: 2026-06-03
Citrix
Citrix Security Bulletin CTX118770
vendor_citrix·CVSS 6.5
CVE-2009-2213 [MEDIUM] Citrix Security Bulletin CTX118770
Citrix Security Bulletin CTX118770
CVE References: CVE-2009-2213, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX121172
vendor_citrix·CVSS 5.0
CVE-2009-2214 [MEDIUM] Citrix Security Bulletin CTX121172
Citrix Security Bulletin CTX121172
CVE References: CVE-2009-2214, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX120742
vendor_citrix·CVSS 10.0
CVE-2009-2452 [CRITICAL] Citrix Security Bulletin CTX120742
Citrix Security Bulletin CTX120742
CVE References: CVE-2009-2452, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
2026-02-06
Published