CERT Polska disclosed CVE-2026-42251, a hard-coded credentials flaw in KAMSOFT KS-SOMED that exposed the FTP server used to host application update packages. The vulnerability affects KSPLUPDFTP.exe through version 30.00.00.056 and ANEKSKLIENT.EXE through version 29.00.02.026. An attacker who obtained the embedded credentials could gain unauthorized access to the update server and upload a malicious package that could later be delivered to client systems as if it were a legitimate software update.
KAMSOFT said it mitigated the issue by removing the hard-coded credentials, changing the update process, and restricting the previously exposed credentials to read-only access. The flaw is tracked as CWE-798 and highlights a software supply-chain risk for organizations running KS-SOMED, because compromise of the update distribution path could enable downstream installation of attacker-controlled code on customer machines.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
CERT Polska disclosed CVE-2026-42251, describing how hard-coded credentials in KS-SOMED could let an attacker upload a malicious update package that might be distributed to client machines as legitimate software. The disclosure identified affected modules and versions in KAMSOFT's software.
The vulnerability record states that CVE-2026-40543, a missing authorization flaw in SOPlanning, was received by cvd@cert.pl. The issue exposed backup-related endpoints to unauthenticated attackers and could allow retrieval of backup archives containing user databases and sensitive configuration data.
KAMSOFT mitigated CVE-2026-42251 by removing the hard-coded credentials, changing the update process, and restricting the previously exposed credentials to read-only access. The flaw affected KSPLUPDFTP.exe through version 30.00.00.056 and ANEKSKLIENT.EXE through version 29.00.02.026.
The vulnerability record states that CVE-2026-42251, a hard-coded credentials flaw in KS-SOMED, was received by cvd@cert.pl. The issue could allow unauthorized access to the FTP server hosting update packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecert.pl
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.