CVE-2026-50741: Revive-Adserver Revive Adserver
High severity, CVSS 8.8. EPSS: 4.9% chance of exploitation in the next 30 days.
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.
Affected products
- Revive-Adserver Revive Adserver: before 6.0.8 (fixed in 6.0.8)
Published 2026-06-26. Last modified 2026-06-29.