CVE-2026-79574

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

  • Published Sep 8, 2026
  • CVSS 9.8 critical
  • 0.7% chance of exploitation in the next 30 days (EPSS)

CVE-2026-79574 at the National Vulnerability Database