
Unauthenticated OS command injection enables RCE in mbCONNECT24
CVEProject published CVE-2026-32968, a critical unauthenticated OS command injection in `com_mb24sysapi` enabling remote code execution on mbCONNECT24-class gateways running firmware `<=2.19.3`.
NewsRemote Code ExecutionIndustrial Systems
2 min23 Mar 2026
