CVE-2026-24712: Northern.tech Cfengine

High severity, CVSS 7.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

Affected products

  • Northern.tech Cfengine: before 3.21.8 (fixed in 3.21.8); from 3.24.0, before 3.24.3 (fixed in 3.24.3); version 3.26.0 only

Published 2026-05-14. Last modified 2026-06-17.