PatchSiren

IceWhaleTech CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL IceWhaleTech CVE published 2026-04-03

CVE-2026-28798

A critical vulnerability was discovered in ZimaOS, a fork of CasaOS, used in Zima devices and x86-64 systems with UEFI. The issue, tracked as CVE-2026-28798, allows an attacker to abuse a proxy endpoint exposed by ZimaOS's web interface to make requests to internal localhost services. This can lead to unauthenticated access to internal-only endpoints and sensitive local services when the product is reacha [truncated]