PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32297 ANGEET CVE debrief

The CVE-2026-32297 vulnerability allows a remote, unauthenticated attacker to write arbitrary files on Angeet ES3 KVM devices, including configuration files and system binaries. This could enable an attacker to gain complete control of a vulnerable system. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on March 17, 2026, and last modified on March 24, 2026. Currently, no fix is available for this vulnerability.

Vendor
ANGEET
Product
Comet KVM
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-17
Original CVE updated
2026-03-24
Advisory published
2026-03-17
Advisory updated
2026-03-24

Who should care

Organizations using Angeet ES3 KVM devices should prioritize patching or mitigating this vulnerability to prevent potential system compromise. Security teams and system administrators responsible for managing KVM devices are particularly concerned. Given the HIGH severity and potential impact, swift action is recommended.

Technical summary

CVE-2026-32297 is an unauthenticated arbitrary file write vulnerability in Angeet ES3 KVM devices. The vulnerability allows remote attackers to write arbitrary files, including configuration files and system binaries, without authentication. This could lead to complete system control if exploited. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N, indicating a Network attack vector with Low complexity and High impact on Integrity. No fix is currently available, and affected products include ANGEET ES3 KVM versions prior to an unspecified fix.

Defensive priority

High priority should be given to identifying and mitigating this vulnerability in Angeet ES3 KVM devices. Organizations should review their inventory for affected devices and consider compensating controls until a patch is available.

Recommended defensive actions

  • Inventory and identify all Angeet ES3 KVM devices within the organization.
  • Implement network segmentation to limit access to KVM devices until a patch is available.
  • Monitor for suspicious activity related to file writes on KVM devices.
  • Consider temporary removal or isolation of KVM devices if feasible.
  • Engage with the vendor for updates on a forthcoming patch.

Evidence notes

The CVE and source item provide details on the vulnerability. The source item, from CISA CSAF, describes the vulnerability and affected products. Multiple references are provided, including the official CVE record and NVD detail. However, the evidence is limited by the lack of a clear fix or detailed affected product information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32297 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32297

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32297 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32297

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-076-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.