Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5967 +1 in the same advisory: …5966 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2024-7694 | Unrestricted File Upload RCE in TeamT5 ThreatSonar Anti-Ransomware TeamT5 ThreatSonar Anti-Ransomware fails to properly validate the content of uploaded files, allowing unrestricted upload of dangerous file types (CWE-434). The flaw is triggered by a remote attacker who already holds administrator privileges on the ThreatSonar platform; after authenticating as an admin, the attacker uploads a malicious file that is used to execute arbitrary system commands on the underlying server. Successful exploitation results in full compromise of the host running the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.2). All deployments of TeamT5 ThreatSonar Anti-Ransomware are affected per CISA; the available data does not specify affected or fixed version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-02-17 following evidence of active exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Apply mitigations per TeamT5's vendor instructions, following CISA BOD 22-01 timelines for federal agencies, or discontinue use of the product if mitigations are unavailable. Restrict and audit administrator accounts on the ThreatSonar platform, review upload activity and system logs for unexpected commands or processes on the host, and verify current mitigation guidance against the latest TeamT5 advisory since specific fixed versions are not listed in this data. | 7.2 | 2% | KEV |
| nichelikely no more than a few thousand deployments, concentrated in Taiwan (estimate; no public install counts) |