CVE-2026-9157 – Web Fax

CVSS 8.4 IMPORTANT

“File upload weaknesses can turn a business communication tool into a remote attack path.”

Gmission released a patch for a high-severity vulnerability affecting Web Fax. CVE-2026-9157 has a CVSS score of 8.4, which is High severity.

The vulnerability involves improper input validation and unrestricted file upload handling that could allow remote code execution in affected Web Fax environments. The update strengthens upload validation and reduces the risk of attackers using crafted files to execute unauthorized code.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-20
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.