CVE-2026-34048
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-34048 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
An attacker can exploit multiple vulnerabilities in Coolify to execute arbitrary code, escalate privileges, disclose information, present false information, manipulate files, conduct a denial of service attack, and bypass security measures.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Coolify to execute arbitrary code and escalate privileges.
- Who is affected
- Deployments of Coolify are affected.
- Urgency
- Remediation is urgent due to the high severity of the vulnerabilities.
- Action
- Apply the latest patches provided by Coolify.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-34048
Get an email if CVE-2026-34048 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-34048 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (2)
- high[NEW] [high] Coolify: Multiple vulnerabilitiescert-bund · 2026-07-10
- criticalCVE-2026-34048: Coolify is an open-source and self-hostable tool for managing servers, applications, and datab…nvd · 2026-07-07
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-34048)