CVE-2026-15545: Shibby Tomato

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.

Affected products

  • Shibby Tomato: version 1.0 only; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.5 only; …

Published 2026-07-13. Last modified 2026-07-13.