CVE-2026-10067: Shibby Tomato

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

Affected products

  • Shibby Tomato: version 1.28 only

Published 2026-05-29. Last modified 2026-07-21.