Revive Adserver disclosed 12 vulnerabilities affecting version 6.0.6 and earlier, including improper access control, improper authentication, blind SQL injection, reflected and stored XSS, remote code execution, and input-validation weaknesses. The most severe issues, CVE-2026-34916 and CVE-2026-44959, allow low-privileged users to inject malicious PHP into the compiledlimitations field and trigger code execution during banner delivery, creating a path from limited access to server-side compromise.
The advisory also details CVE-2026-34917, an authentication flaw that allows low-privileged web admin session IDs to be reused against the XML-RPC API, potentially enabling abuse of API-level functions. Additional bugs include a blind SQL injection in zone-include.php, several access-control issues that can alter ownership relationships or banner activation state, and stored or reflected XSS that can execute when administrators view audit or email log details. Revive Adserver said the flaws were reported through HackerOne by multiple researchers and were fixed in version 6.0.7 and later, urging users to upgrade to the latest release.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The advisory stated that fixes for the disclosed vulnerabilities were implemented and are available in Revive Adserver version 6.0.7 and later. Revive Adserver recommended upgrading to version 6.0.7 or the latest available release.
On 2026-06-03, Revive Adserver published security advisory REVIVE-SA-2026-002 disclosing 12 vulnerabilities affecting version 6.0.6 and earlier, including access control, authentication, SQL injection, XSS, and remote code execution issues. The advisory identified CVE-2026-34916 and CVE-2026-44959 as the most severe flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.