Galaxy Software Services' Vitals ESP is affected by two high-severity vulnerabilities that could let remote attackers access sensitive functions and elevate privileges. CVE-2026-4640 is a missing authentication flaw (CWE-306) that allows unauthenticated attackers to remotely execute certain functions and obtain sensitive information, with CVSS vectors indicating network-based exploitation, low attack complexity, and no required user interaction or privileges.
A second issue, CVE-2026-4639, is an incorrect authorization vulnerability (CWE-863) that allows authenticated remote attackers to perform administrative functions and escalate privileges. TWCERT/CC published references for both flaws in English and Chinese, and the scoring for each indicates material risk to confidentiality, integrity, and availability in deployments of Vitals ESP.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Also on 2026-03-24, TWCERT/CC published English and Chinese references for the two Vitals ESP vulnerabilities and documented their CWE classifications and high-severity CVSS vectors. The disclosures identified CVE-2026-4639 as CWE-863 and CVE-2026-4640 as CWE-306.
On 2026-03-24, TWCERT/CC received CVE-2026-4640 describing a missing authentication vulnerability in Galaxy Software Services' ESP. The flaw allows unauthenticated remote attackers to execute certain functions and obtain sensitive information.
On 2026-03-24, TWCERT/CC received CVE-2026-4639 describing an incorrect authorization vulnerability in Galaxy Software Services' ESP. The flaw allows authenticated remote attackers to perform certain administrative functions and escalate privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.