CVE-2026-64940
CVE-2026-64940 is a high-severity vulnerability with a CVSS 3.x base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-625.
Key facts
- Severity: High (CVSS 3.x base score 8.6)
- CVSS v4: 8.8
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-625
- Published:
- Last modified:
Description
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
Frequently asked questions
- What is CVE-2026-64940?
- Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
- How severe is CVE-2026-64940?
- CVE-2026-64940 has a CVSS 3.x base score of 8.6, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity high, and availability low.
- Is CVE-2026-64940 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-64940?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-64940 published?
- CVE-2026-64940 was published on 2026-08-10.
References
Other CWE-625 vulnerabilities
- CVE-2026-32973 — Critical (CVSS 9.8): OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly…
- CVE-2018-8926 — High (CVSS 8.8): Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and…
- CVE-2026-19278 — Medium (CVSS 6.8): A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator…
- CVE-2026-23651 — Medium (CVSS 6.7): Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- CVE-2020-8910 — Medium (CVSS 6.5): A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker…
- CVE-2026-34830 — Medium (CVSS 5.9): Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path…