cvedb.io
CVE-2026-17032
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-08-06T22:16:49.237 · Last modified 2026-08-06T22:16:49.237

Summary

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.