Skip to main content
CRITICAL

CVE-2026-26068

emp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection)

CVSS v3

9.9

CRITICAL

EPSS Score

3.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.

Technical details

Published
2026-02-12
Last Modified
2026-02-25

Frequently asked questions

What is CVE-2026-26068?

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is accepted during check-in and later interpolated into tmux shell command strings executed via /bin/sh -c. This enables command injection and remote code execution on the operator host. This vulnerability is fixed in 3.21.1.

Is CVE-2026-26068 actively exploited?

A proof-of-concept exploit exists for CVE-2026-26068, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-26068?

CVE-2026-26068 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2026-26068 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key