CVE-2026-103432: Apcupsd

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.

Affected products

  • Apcupsd Apcupsd: up to and including 3.14.14

Published 2026-09-30. Last modified 2026-09-30.