CVE-2026-6847 is a remote code execution vulnerability in 4real ThemisNETPanel caused by missing authentication on a critical file upload function. A network-accessible endpoint permits unauthenticated attackers to submit a base64-encoded payload that is processed as an arbitrary PHP file upload. Because the uploaded server-side code can then be executed by the application environment, an attacker can achieve arbitrary code execution on the underlying server. The issue affects ThemisNETPanel versions earlier than 04.2026.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability affecting 4real ThemisNETPanel software.
A remote code execution vulnerability in 4real ThemisNETPanel caused by missing authentication on a critical file upload function, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.