Two high-severity vulnerabilities were disclosed in Roxy-WI, the web interface used to manage HAProxy, Nginx, Apache, and Keepalived. The issues affect versions prior to 8.2.6.4 and were published as CVE-2026-33076 and CVE-2026-33078. The first flaw is a path traversal issue in the haproxy_section_save interface that can let an attacker write arbitrary files, including into scheduled task locations, creating a path to remote code execution.
The second flaw is a SQL injection vulnerability in the same haproxy_section_save functionality, where the server_ip parameter is passed unsanitized through multiple calls and inserted into a database query using Python string formatting. Both bugs are remotely exploitable with low attack complexity and can severely affect confidentiality, integrity, and availability. The vendor addressed both issues in Roxy-WI 8.2.6.4, with a patch commit and security advisory published alongside the disclosures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Two high-severity vulnerabilities affecting Roxy-WI versions prior to 8.2.6.4 were published: CVE-2026-33076, a path traversal that can enable arbitrary file writing and remote code execution, and CVE-2026-33078, a SQL injection vulnerability in haproxy_section_save. Both disclosures describe network-exploitable flaws with low attack complexity and high impact.
Roxy-WI version 8.2.6.4 was released to remediate a path traversal/arbitrary file write issue in haproxy_section_save and a SQL injection flaw involving the unsanitized server_ip parameter. The fixes were accompanied by a patch commit and security advisory references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.