CVE-2024-9129: Zend Server

Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

Affected products

  • Zend Zend Server: from 8.5, before 9.1 (fixed in 9.1)

Published 2024-10-22. Last modified 2026-06-17.