PatchSiren

Mobatek CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Mobatek CVE published 2026-06-12

CVE-2026-11967

CVE-2026-11967 is a HIGH severity vulnerability in MobaXterm Personal Edition (Portable) 26.3 Build 5154. The vulnerability allows arbitrary code execution by loading a malicious DLL located in the same directory as the portable executable. The application automatically loads the winspool.drv library from that location during startup, enabling an attacker with local access to place a specially crafted DLL [truncated]

HIGH Mobatek CVE published 2026-06-12

CVE-2026-11879

CVE-2026-11879 is a HIGH-severity vulnerability in MobaXterm Personal Edition (Portable) version 26.3 (Build 5154). The vulnerability allows arbitrary code execution by loading malicious DLLs from a temporary directory that is predictable and can be modified by the user. During startup, the application searches for specific DLLs in this location before resorting to the system’s secure paths, enabling an a [truncated]

CRITICAL Mobatek CVE published 2026-06-04

CVE-2019-25741

CVE-2019-25741 is a structured exception handling (SEH) based buffer overflow vulnerability in Mobatek MobaXterm 12.1. The vulnerability is triggered when a malicious MobaXterm sessions file with overflow data is imported and executed, enabling reverse shell execution with user privileges. The vulnerability has a CVSS score of 9.3 and is classified as CRITICAL.