PatchSiren cyber security CVE debrief
CVE-2026-75332 Zyplayer-Doc CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T23:17:18.657Z and has not been modified since then. This critical SSRF vulnerability affects Zyplayer-Doc version 1.0.0 or earlier via the WikiPageWebService.download() method, allowing attackers to potentially access unauthorized resources. Organizations should prioritize inventory checks and consider compensating controls due to the critical severity of this vulnerability. The CVE Program and NIST NVD have provided official records and assessments of this vulnerability. Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity related to WikiPageWebService.download(). Evidence is limited; primary official records indicate a critical SSRF vulnerability in Zyplayer-Doc version 1.0.0 or earlier via WikiPageWebService.download().
- Vendor
- Zyplayer-Doc
- Product
- Zyplayer-Doc
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-08-31
Who should care
Organizations using Zyplayer-Doc version 1.0.0 or earlier should be aware of this critical SSRF vulnerability and take immediate action to mitigate potential risks. This includes operators, platform administrators, vulnerability management teams, and security personnel responsible for ensuring the security and integrity of affected systems. They should prioritize inventory checks, consider compensating controls, and monitor for suspicious activity related to WikiPageWebService.download().
Technical summary
Zyplayer-Doc version 1.0.0 or earlier is vulnerable to Server-Side Request Forgery (SSRF) via the WikiPageWebService.download() method. This critical vulnerability has a CVSS score of 9.1 and can allow attackers to access unauthorized resources. The vulnerability is considered critical due to its potential impact on affected systems. Organizations using Zyplayer-Doc version 1.0.0 or earlier should be aware of this vulnerability and take immediate action to mitigate potential risks. This includes operators, platform administrators, vulnerability management teams, and security personnel responsible for ensuring the security and integrity of affected systems.
Defensive priority
Organizations using Zyplayer-Doc version 1.0.0 or earlier should prioritize immediate inventory checks and consider compensating controls due to the critical severity of this SSRF vulnerability.
Recommended defensive actions
- Inventory checks for Zyplayer-Doc version 1.0.0 or earlier
- Consider compensating controls for SSRF vulnerabilities
- Monitoring for suspicious activity related to WikiPageWebService.download()
Evidence notes
Evidence is limited; primary official records indicate a critical SSRF vulnerability in Zyplayer-Doc version 1.0.0 or earlier via WikiPageWebService.download(). Defenders should verify affected product deployments, review official advisories, and monitor for suspicious activity. Additional context from source references may be necessary for comprehensive risk assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75332 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75332
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75332 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75332
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fangtang7/CVE/blob/main/Zyplayer-Doc/Zyplayer-Doc.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.