Researchers disclosed a pre-authentication remote code execution chain affecting SysAid On-Premise, showing that unauthenticated attackers could reach code execution through the product’s support ticket-related functionality. The issue was publicly described by WatchTowr Labs and Summoning Team under the title “SysOwned, Your Friendly Support Ticket,” with CVE-2025-2775 identified as a key part of the exploit chain alongside additional related flaws.
The reports indicate the vulnerability chain can be triggered without prior authentication, making internet-exposed SysAid On-Premise deployments a high-risk target because attackers may be able to compromise servers directly through the application. Public disclosure by multiple security researchers increases the likelihood of defender scrutiny and attacker interest, particularly for organizations relying on on-premises help desk infrastructure.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Security researchers disclosed a pre-authentication remote code execution chain affecting SysAid On-Premise. The chain includes CVE-2025-2775 and additional related flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.