The Exploit Bulletin — Sunday, September 27, 2026: 1 issue requires action
Sunday, September 27, 2026 — 1 issue requires action. If you run none of the software below, you are done.
Affects: Proxmox Virtual Environment
1. Unauthenticated login bypass via tfa-challenge parameter in Proxmox VE 7.x/8.0 gives root@pam access, with ransomware use reported (CVE-2023-54391)
AUTHENTICATION BYPASS · CRITICAL · CVSS 9.3
VulnCheck lists this bypass as exploited with known ransomware use and a Proxmox forum report describes an EOL PVE 7 host being encrypted after compromise, so any still-running 7.x/8.0 host whose management API is reachable can be taken over as root by anyone who sends one POST.
Proxmox VE 7.0–7.4 and 8.0 (libpve-access-control before 8.0.4) accept an arbitrary tfa-challenge value on the API access-ticket login endpoint and skip password verification, letting an unauthenticated attacker obtain a ticket for any enabled user without a second factor, including root@pam. All affected releases are end of life; a Proxmox forum user reports an EOL PVE 7 host being encrypted and ransomed.
Affected: Proxmox Virtual Environment (VE) 7.0 through 7.4; Proxmox Virtual Environment (VE) 8.0 (libpve-access-control before 8.0.4)
How to Test: Check the installed libpve-access-control package version on every node: anything below 8.0.4 on PVE 7.x or 8.0 is affected. Review the API/proxy logs for POST requests to the access ticket (login) endpoint carrying a tfa-challenge parameter from unexpected sources, look for unexplained root@pam sessions, and check for ransom notes or encrypted VM storage as described in the forum report.
How to Patch: Upgrade to libpve-access-control 8.0.4 or later (i.e. a supported Proxmox VE 8.x release); PVE 7.x is end of life and must be migrated to a supported version. Until upgraded, remove the management API from internet and untrusted-network reachability.
Evidence: VulnCheck KEV · Proxmox forum report of EOL PVE 7 host encrypted and ransomed via unauthenticated compromise · GreyNoise threat-signal blog cited by VulnCheck KEV as exploitation source
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].