CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-19036

highCVSS 7.2covered by 1 sourcefirst seen 2026-08-06
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

⚡ Watch CVE-2026-19036

Get an email if CVE-2026-19036 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-19036

CVE.org record

Embed the live status

CVE-2026-19036 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-19036 status](https://www.csirts.com/badge/CVE-2026-19036)](https://www.csirts.com/cve/CVE-2026-19036)