CVE-2026-49243: Webmin
Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
Affected products
- Webmin Webmin: before 2.650 (fixed in 2.650)
Published 2026-09-29. Last modified 2026-10-09.