A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 26.2 is able to mitigate this issue. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Rust payload loaders related to claimed MobaXterm DLL hijacking exploitation for CVE-2026-6421. The top-level README is minimal. The rustloader subproject is a standalone Windows GUI executable using reqwest and WinAPI to fetch shellcode from a hardcoded HTTPS URL, allocate RW memory with VirtualAlloc, copy the payload, switch memory to executable with VirtualProtect, and execute it indirectly through a SetTimer callback and message loop. It then keeps the process alive indefinitely. This is a fileless in-memory loader with a fixed remote payload source. The zloader subproject is a Rust cdylib intended for DLL hijacking on Windows x86 against MobaXterm Home Edition <= 26.1. It includes a build script and a large lib.rs implementing malicious DLL behavior. Based on the visible code and comments, it performs anti-debugging and anti-sandbox checks (debugger presence, sleep timing acceleration, suspicious foreground window titles, limited user-interaction heuristics), writes diagnostic output to OutputDebugStringA and a local ZLoader.log file, downloads shellcode from a second hardcoded HTTPS URL, and executes it in memory using WinAPI primitives such as VirtualAlloc, VirtualProtect, CreateThread, and WaitForSingleObject. It also exposes numerous forwarded exports such as AlphaBlend and TransparentBlt so the host application can continue operating while the malicious DLL runs, which is characteristic of DLL proxy/hijack loaders. Overall, this is not a benign test harness or detector; it is operational exploit-support malware code designed to achieve code execution on Windows through DLL hijacking and remote shellcode staging.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.