NCSC-2026-0333 [1.00] [M/H] Vulnerabilities patched in CodeMeter Runtime from Wibu-Systems
Wibu-Systems has patched multiple vulnerabilities in CodeMeter Runtime. The vulnerabilities are located in different components of CodeMeter Runtime, particularly in versions prior to 8.41a and 9.10. A local attacker can exploit improper verification of NTFS reparse points when creating temporary files by cmu.exe, which can lead to the deletion of arbitrary system files with System privileges and thus local privilege escalation. Additionally, the configuration command handler contains a flaw that prevents network restrictions from being correctly enforced, allowing a remote attacker to obtain unauthorized access to sensitive configuration data and control over the WebAdmin interface. Furthermore, there is an input sanitization issue in the logger module that allows format specifiers to be injected, which can lead to crashes and possible information leaks, both locally and remotely, especially in combination with CVE-2026-81573. There is also missing proper bounds checking on the data length in opcode 0x5e requests, which can cause a segmentation fault and affect the stability of the server component. Finally, a weak SID is used for authentication, allowing brute-force attacks to gain access to session handles and thus license information from other sessions.
CSIRTS triage
- What
- CodeMeter Runtime contains improper NTFS reparse point verification, network restriction bypass, and format string injection vulnerabilities allowing privilege escalation, unauthorized configuration access, and information disclosure.
- Who is affected
- Systems running CodeMeter Runtime versions prior to 8.41a and 9.10; local attackers can escalate to system privileges, remote attackers can access WebAdmin.
- Urgency
- High; local privilege escalation and remote configuration access vulnerabilities in privileged software.
- Action
- Update CodeMeter Runtime to version 8.41a or 9.10 or later addressing CVE-2026-81573.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CodeMeter Runtime
Get an email when a new CodeMeter Runtime advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0333
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-815730.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81573 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from NCSC-NL Advisories
- unknownNCSC-2026-0337 [1.00] [H/H] Zero-Day vulnerabilities patched in SonicWall SMA1000 Appliance2026-09-02
- unknownNCSC-2026-0336 [1.00] [M/H] Vulnerability patched in JFrog Artifactory2026-09-02
- unknownNCSC-2026-0335 [1.00] [M/H] Vulnerabilities fixed in WatchGuard Fireware OS2026-09-01
- unknownNCSC-2026-0334 [1.00] [M/H] Vulnerabilities patched in PaperCut MF and PaperCut NG from PaperCut2026-08-28
- unknownNCSC-2026-0289 [1.01] [H/H] Vulnerabilities patched in Microsoft Exchange Server2026-08-28