CVE-2026-21640: Aquaplatform Revive Adserver

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.

Affected products

  • Aquaplatform Revive Adserver: from 6.0.0, up to and including 6.0.4

Published 2026-01-20. Last modified 2026-06-17.