PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11967 Mobatek CVE debrief

CVE-2026-11967 is a HIGH severity vulnerability in MobaXterm Personal Edition (Portable) 26.3 Build 5154. The vulnerability allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. The application automatically loads the winspool.drv library from that location during startup, enabling an attacker with local access to place a specially crafted DLL alongside the executable to be executed when the victim launches the application.

Vendor
Mobatek
Product
MobaXterm Personal Edition (Portable)
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-12
Advisory published
2026-06-12
Advisory updated
2026-06-12

Who should care

Users of MobaXterm Personal Edition (Portable) 26.3 Build 5154, administrators of systems where this software is used, and security teams responsible for patching and vulnerability management.

Technical summary

The vulnerability exists due to the application's automatic loading of the winspool.drv library from the same directory as the portable executable. An attacker with local access can exploit this by placing a specially crafted DLL alongside the executable, which will be executed when the victim launches the application.

Defensive priority

HIGH

Recommended defensive actions

  • Apply the vendor's official patch or update to a version that addresses this vulnerability.
  • Ensure that only trusted DLLs are loaded by the application.
  • Restrict access to the directory containing the portable executable to prevent unauthorized DLL placement.
  • Monitor for suspicious activity related to the application and its directory.

Evidence notes

The CVE-2026-11967 vulnerability was reported by Incibe and has a CVSS score of 8.5. The vulnerability is categorized under CWE-427.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11967 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11967

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11967 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11967

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-mobateks-mobaxterm-personal-edition-portable

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.