CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54735

criticalCVSS 10covered by 2 sourcesfirst seen 2026-07-29
Impact Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. Patches Patched in v4.4.0 Workarounds If one is unable to update, please make sure that the affected bidder adapters are disabled.

⚡ Watch CVE-2026-54735

Get an email if CVE-2026-54735 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54735

CVE.org record

Embed the live status

CVE-2026-54735 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54735 status](https://www.csirts.com/badge/CVE-2026-54735)](https://www.csirts.com/cve/CVE-2026-54735)