VDB

GCVE-110-OSM-2026-11972

GCVE-110-OSM-2026-11972
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 11, 2026
Part of a mass campaign run from GitHub account tesssmax (id 301410327) spanning 2026-07-21 to 2026-09-08 across dozens of repositories (installer2-installer49, minus gaps) that distribute fake installers/droppers silently installing a ScreenConnect RMM client disguised as "Feedback Tool" (Windows service FeedbackToolSvc_NN), phoning home to www.somtinn.com:8041 (ScreenConnect instance ID 008c4a1933454b9c) as a Guest session. This specific repo's GitHub Release was retracted/emptied before an asset could be collected, but it shares the same actor, numbering sequence, and creation pattern as the rest of the campaign. Included for campaign infrastructure tracking. See github.com/tesssmax/installer47 (OSM threat_id 15a928c5-8a9a-4364-af60-e112aaf26e0f) for a previously-reported sibling in this same campaign. No release asset currently published for this repository (empty/retracted GitHub Release). Repo is part of the same tesssmax installerN numbering sequence and account as the rest of the Feedback Tool / ScreenConnect campaign (see companion repos and blog writeup); included for campaign infrastructure tracking even though no live payload was recovered from it.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

506 records in the GCVE database · Updated September 11, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›