CVE-2025-8760: Instar 2k+
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.
Affected products
Published 2025-08-13. Last modified 2026-06-17.