CVE-2026-67595
HIGH EXPLOITEDVaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
Title source: cnaExploitation Summary
CVE-2026-67595 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/vaahcms-malicious-javascript-supply-chain-via-security-otp-blade-php
Scores
CVSS v3
8.1
EPSS
0.0042
EPSS Percentile
34.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2026-07-29
CWE
CWE-506
Status
published
Products (2)
webreinvent/vaahcms
2.0.0 - 2.3.4
webreinvent/vaahcms
8d7898f7a385a5fade1180a9b664ff158d873129
Published
Jul 29, 2026
Tracked Since
Jul 30, 2026