CVE-2026-7280: Empia Technology Avacast
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to place a malicious executable file in a specific directory, resulting in arbitrary code execution with system privileges when the AVACAST service starts.
Affected products
- Empia Technology Avacast: up to and including 5.10.10.43
Published 2026-04-28. Last modified 2026-06-17.