CVE-2026-27975: Ajenti

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.

Affected products

  • Ajenti Ajenti: before 2.2.13 (fixed in 2.2.13)

Published 2026-02-26. Last modified 2026-06-17.