RATOC Systems' RAID Monitoring Manager for Windows is affected by two high-severity installer vulnerabilities that can let attackers execute arbitrary code with elevated privileges. CVE-2026-32680 is a local privilege escalation flaw tied to custom installation paths: when the software is installed outside the default directory, insecure ACLs can leave the target folder writable by non-administrative users, creating a path to SYSTEM-level code execution. The issue is classified as CWE-276 and carries high impact across confidentiality, integrity, and availability.
A second flaw, CVE-2026-28760, affects the same installer through improper DLL loading. The installer searches the current directory for certain DLLs, so an attacker who places a crafted DLL next to the installer and convinces a user to run it can achieve arbitrary code execution with administrator privileges. That issue is classified as CWE-427, and both vulnerabilities were published through JPCERT/JVN-linked advisories and RATOC references as high-severity Windows privilege-escalation risks.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-26, JPCERT/CC received a report for CVE-2026-32680 affecting the RATOC RAID Monitoring Manager for Windows installer. The vulnerability involves insecure ACLs on a user-selected non-default installation directory, which can let non-administrative users modify contents and potentially execute code with SYSTEM privileges.
On 2026-03-26, JPCERT/CC received a report for CVE-2026-28760 affecting the RATOC RAID Monitoring Manager for Windows installer. The flaw is a DLL search order issue that can allow arbitrary code execution with administrator privileges if a crafted DLL is placed alongside the installer and a user runs it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.