CVE-2023-26266: Afl++ Project Afl++

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.

Affected products

Published 2023-02-21. Last modified 2026-06-17.