CVE-2026-26201: JM33-m0 EMP3R0R

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activity, Go runtime can trigger `fatal error: concurrent map read and map write`, causing C2 process crash (availability loss). Version 3.21.2 fixes this issue.

Affected products

  • JM33-m0 EMP3R0R: before 3.21.2 (fixed in 3.21.2)

Published 2026-02-19. Last modified 2026-06-17.