CVE-2026-36574
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary cod
CVSS
7.8
High
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Jun 3, 2026 · Last modified: Jul 22, 2026 · CWE-427
0.1%EPSS · 30 days0.1%
2026-06-302026-07-25
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.
- github.comhttps://github.com/Wassimulator/CactusViewer
- github.comhttps://github.com/Wassimulator/CactusViewer/issues/65
- github.comhttps://github.com/Wassimulator/CactusViewer/releases/download/v2.3.0/CactusViewer.exe
- github.comhttps://github.com/openlabs/docker-wkhtmltopdf-aas/issues/36
- github.comhttps://github.com/Wassimulator/CactusViewer/issues/65
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-165197.3 HIG2.0%
——1A
DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility
desktop application. The application loads one or more dynamic-link libraries
(DLLs) from an unsafe search path, allowing a local attacker to place a
malicious DLL in a location searched before the legitimate library
location.2dCVE-2026-217706.5 MED1.5%
——0HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.9dCVE-2026-56748.8 HIG2.2%
——1A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.10dCVE-2026-429367.8 HIG3.9%
——1The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.11dCVE-2026-482727.8 HIG3.5%
——1Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.10dCVE-2026-04878.4 HIG5.3%
——2SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.6d