Remote Code Execution Vulnerability in Furion .NET Framework by Furion
CVE-2026-108570

5.3MEDIUM

Key Information:

Vendor

Furion

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108570?

A vulnerability has been identified in the Furion .NET Framework, specifically in the RunCompile function of the View Engine component. This flaw occurs due to improper handling of special elements within the template engine, allowing attackers to manipulate the content argument. The exploit is particularly concerning as it can be executed remotely, posing significant risks to systems using affected versions of the framework. Despite early disclosures to the vendor, no response has been received, raising alarms about the potential for public exploitations.

Affected Version(s)

.NET Framework 4.9.9.0

.NET Framework 4.9.9.1

.NET Framework 4.9.9.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlackSpdier (VulDB User)
VulDB CNA Team
.