CVE-2026-32999: WebPros Comet Backup
Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.
Affected products
- WebPros Comet Backup: before 26.4.3 (fixed in 26.4.3); before 26.5.0 (fixed in 26.5.0)
Published 2026-05-28. Last modified 2026-06-17.