CVE-2026-27884 affects NetExec prior to version 1.5.1 in the spider_plus module. When spider_plus crawls SMB shares and saves downloaded files locally, it improperly constructs the output file and directory path and fails to account for SMB filenames containing path traversal sequences such as ../. Because Linux SMB shares can expose filenames with these characters, a maliciously crafted filename on a target SMB share can cause spider_plus to write outside the intended download directory. This results in an arbitrary file write or overwrite condition on the system running NetExec when spider_plus is used with file downloading enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit consisting primarily of a single executable file, main.py. The code sets up a malicious SMB server using Impacket's SimpleSMBServer and is explicitly designed to exploit an arbitrary file write issue in NetExec's spider_plus module, identified in the source comments as CVE-2026-27884. The repository has minimal project scaffolding: an empty README, a pyproject.toml, a lock file, and no additional modules or payload components. The exploit works by monkey-patching impacket.smbserver.isInFileJail to always return True, disabling path traversal protections in the SMB server implementation for this process. It then creates a nested share directory under the user's home directory (~/1/2/3/4/5) and writes a file using a traversal-based relative path (..\..\..\..\..\nxc_test_exploit.txt). This is intended to demonstrate that when the vulnerable spider_plus functionality interacts with the malicious SMB share, attacker-controlled file paths can escape the intended directory and write arbitrary content. The payload is simple and hardcoded: the string "Arbitrary file write :D \n". Operationally, the script binds an SMB listener on 0.0.0.0:445, exports the crafted share named "Netexec POC", enables SMB2 support, and starts serving. The console output instructs the operator to run NetExec against the server using guest authentication and the spider_plus module with DOWNLOAD=true. On shutdown, the script removes the temporary ~/1 directory tree. This is a real exploit PoC rather than a detector: it provides a working malicious service and a concrete arbitrary-write demonstration, but it is not heavily weaponized or configurable.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.