PatchSiren

Crocus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Crocus CVE published 2026-07-21

CVE-2026-52470

A critical SQL injection vulnerability was found in Crocus v.1.3.44. The vulnerability allows a remote attacker to escalate privileges via the RecordStateMapper.xml file. The CVE record was published on 2026-07-21T21:16:51.873Z and was last modified on 2026-07-22T20:50:36.493Z. This vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Security teams should prioritize patching to prevent po [truncated]

CRITICAL Crocus CVE published 2026-07-21

CVE-2026-52469

A SQL injection vulnerability was reported in Crocus v.1.3.44. The vulnerability allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file. The CVE record was published on 2026-07-21T21:16:51.760Z and has not been modified since then. This issue is critical with a CVSS score of 9.8. Users should assess their exposure and apply patches or mitigations as necessary. Limited additional [truncated]