CVE-2017-1000486: Primetek Primefaces Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-01-10. EPSS: 94.1% chance of exploitation in the next 30 days.
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Affected products
- Primetek Primefaces: from 4.0, up to and including 4.0.24; from 5.0, before 5.2.21 (fixed in 5.2.21); from 5.3, before 5.3.8 (fixed in 5.3.8)
Published 2018-01-03. Last modified 2026-06-17.