CVE-2026-7280: Empia Technology Avacast

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.

Affected products

Published 2026-04-28. Last modified 2026-06-17.