CVE-2026-17032: Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17032?
CVE-2026-17032 has a critical severity rating of 9.8.
How do I fix CVE-2026-17032?
To mitigate CVE-2026-17032, immediately remove the affected Supsystic Pro plugins and replace them with clean, verified versions.
What systems are affected by CVE-2026-17032?
CVE-2026-17032 affects all installations of Supsystic Multiple Pro Plugins distributed through the compromised vendor update server.
What type of vulnerability is CVE-2026-17032?
CVE-2026-17032 is a backdoor vulnerability that allows unauthenticated attackers to gain full control of affected sites.
What kind of data can be exfiltrated due to CVE-2026-17032?
CVE-2026-17032 can exfiltrate sensitive data such as user credentials and other confidential information.