CVE-2025-56333: Pangolin

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

Affected products

  • Pangolin Pangolin: before 1.7.0 (fixed in 1.7.0)

Published 2025-12-29. Last modified 2026-06-17.