CVE-2026-14261: exploitation status and patch state
CVE-2026-14261 · CVSS 9.1 CRITICAL · EPSS 1%
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
Is CVE-2026-14261 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.