CVE-2026-16097: Shibby Tomato

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.

Affected products

  • Shibby Tomato: version 1.28 only

Published 2026-07-18. Last modified 2026-07-20.