PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75332 Zyplayer-Doc CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T23:17:18.657Z and has not been modified since then. This critical SSRF vulnerability affects Zyplayer-Doc version 1.0.0 or earlier via the WikiPageWebService.download() method, allowing attackers to potentially access unauthorized resources. Organizations should prioritize inventory checks and consider compensating controls due to the critical severity of this vulnerability. The CVE Program and NIST NVD have provided official records and assessments of this vulnerability. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity related to WikiPageWebService.download(). Evidence is limited; primary official records indicate a critical SSRF vulnerability in Zyplayer-Doc version 1.0.0 or earlier via WikiPageWebService.download().

Vendor
Zyplayer-Doc
Product
Zyplayer-Doc
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-08-31
Advisory published
2026-08-26
Advisory updated
2026-08-31

Who should care

Organizations using Zyplayer-Doc version 1.0.0 or earlier should be aware of this critical SSRF vulnerability and take immediate action to mitigate potential risks. This includes operators, platform administrators, vulnerability management teams, and security personnel responsible for ensuring the security and integrity of affected systems. They should prioritize inventory checks, consider compensating controls, and monitor for suspicious activity related to WikiPageWebService.download().

Technical summary

Zyplayer-Doc version 1.0.0 or earlier is vulnerable to Server-Side Request Forgery (SSRF) via the WikiPageWebService.download() method. This critical vulnerability has a CVSS score of 9.1 and can allow attackers to access unauthorized resources. The vulnerability is considered critical due to its potential impact on affected systems. Organizations using Zyplayer-Doc version 1.0.0 or earlier should be aware of this vulnerability and take immediate action to mitigate potential risks. This includes operators, platform administrators, vulnerability management teams, and security personnel responsible for ensuring the security and integrity of affected systems.

Defensive priority

Organizations using Zyplayer-Doc version 1.0.0 or earlier should prioritize immediate inventory checks and consider compensating controls due to the critical severity of this SSRF vulnerability.

Recommended defensive actions

  • Inventory checks for Zyplayer-Doc version 1.0.0 or earlier
  • Consider compensating controls for SSRF vulnerabilities
  • Monitoring for suspicious activity related to WikiPageWebService.download()

Evidence notes

Evidence is limited; primary official records indicate a critical SSRF vulnerability in Zyplayer-Doc version 1.0.0 or earlier via WikiPageWebService.download(). Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity. Additional context from source references may be necessary for comprehensive risk assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75332 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75332

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75332 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75332

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.