PatchSiren

Supsystic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Supsystic CVE published 2026-08-06

CVE-2026-17032

Multiple Supsystic Pro plugins were compromised through a malicious update server, allowing unauthenticated attackers to deploy a second-stage payload. This critical vulnerability, with a CVSS score of 9.8, enables attackers to exfiltrate credentials and gain full control of affected sites. Administrators and users of these plugins must take immediate action to protect their sites. The CVE record was publ [truncated]