VDB
GCVE-110-OSM-2026-11972
GCVE-110-OSM-2026-11972
Advisory PublishedCVSS 8.8/10
Part of a mass campaign run from GitHub account tesssmax (id 301410327) spanning 2026-07-21 to 2026-09-08 across dozens of repositories (installer2-installer49, minus gaps) that distribute fake installers/droppers silently installing a ScreenConnect RMM client disguised as "Feedback Tool" (Windows service FeedbackToolSvc_NN), phoning home to www.somtinn.com:8041 (ScreenConnect instance ID 008c4a1933454b9c) as a Guest session. This specific repo's GitHub Release was retracted/emptied before an asset could be collected, but it shares the same actor, numbering sequence, and creation pattern as the rest of the campaign. Included for campaign infrastructure tracking. See github.com/tesssmax/installer47 (OSM threat_id 15a928c5-8a9a-4364-af60-e112aaf26e0f) for a previously-reported sibling in this same campaign.
No release asset currently published for this repository (empty/retracted GitHub Release). Repo is part of the same tesssmax installerN numbering sequence and account as the rest of the Feedback Tool / ScreenConnect campaign (see companion repos and blog writeup); included for campaign infrastructure tracking even though no live payload was recovered from it.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
506 records in the GCVE database · Updated September 11, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.