VDB
GCVE-110-OSM-2026-786
GCVE-110-OSM-2026-786
Advisory PublishedCVSS 9.6/10
Malicious Zendesk API client library targeting customer support integrations. Supply chain attack with MSBuild-based code execution compromising support infrastructure.
Exploits NuGet's MSBuild integration by placing malicious code in .targets files as inline tasks. When projects build, MSBuild automatically imports and executes these tasks, downloading .NET executables from throwaway GitHub repositories with embedded obfuscated command-line payloads.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | ZendeskApi.Client.V2 | all (affected) | — |
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.