The Exploit Bulletin

Archives
Log in
Subscribe
September 27, 2026

The Exploit Bulletin — Sunday, September 27, 2026: 1 issue requires action

Sunday, September 27, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: Proxmox Virtual Environment


1. Unauthenticated login bypass via tfa-challenge parameter in Proxmox VE 7.x/8.0 gives root@pam access, with ransomware use reported (CVE-2023-54391)

AUTHENTICATION BYPASS · CRITICAL · CVSS 9.3

VulnCheck lists this bypass as exploited with known ransomware use and a Proxmox forum report describes an EOL PVE 7 host being encrypted after compromise, so any still-running 7.x/8.0 host whose management API is reachable can be taken over as root by anyone who sends one POST.

Proxmox VE 7.0–7.4 and 8.0 (libpve-access-control before 8.0.4) accept an arbitrary tfa-challenge value on the API access-ticket login endpoint and skip password verification, letting an unauthenticated attacker obtain a ticket for any enabled user without a second factor, including root@pam. All affected releases are end of life; a Proxmox forum user reports an EOL PVE 7 host being encrypted and ransomed.

Affected: Proxmox Virtual Environment (VE) 7.0 through 7.4; Proxmox Virtual Environment (VE) 8.0 (libpve-access-control before 8.0.4)

How to Test: Check the installed libpve-access-control package version on every node: anything below 8.0.4 on PVE 7.x or 8.0 is affected. Review the API/proxy logs for POST requests to the access ticket (login) endpoint carrying a tfa-challenge parameter from unexpected sources, look for unexplained root@pam sessions, and check for ransom notes or encrypted VM storage as described in the forum report.

How to Patch: Upgrade to libpve-access-control 8.0.4 or later (i.e. a supported Proxmox VE 8.x release); PVE 7.x is end of life and must be migrated to a supported version. Until upgraded, remove the management API from internet and untrusted-network reachability.

Evidence: VulnCheck KEV · Proxmox forum report of EOL PVE 7 host encrypted and ransomed via unauthenticated compromise · GreyNoise threat-signal blog cited by VulnCheck KEV as exploitation source

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Monday, September 28, 2026: 1 issue requires action Older → The Exploit Bulletin — Saturday, September 26, 2026: all clear
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.