CVE-2024-28211: Naver Ngrinder

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.

Affected products

  • Naver Ngrinder: before 3.5.9 (fixed in 3.5.9)

Published 2024-03-07. Last modified 2026-06-17.