PT-2026-3861 · Unknown · Nexusflow Api Gateway

Published

2026-01-21

·

Updated

2026-05-27

·

CVE-2026-12345

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions NexusFlow API Gateway versions prior to 3.8.1
Description A critical remote code execution issue exists in NexusFlow API Gateway. This issue is actively exploited by unauthenticated attackers, allowing them to gain full control of servers. The issue is identified as a zero-day with a CVSS score of 10.0. The affected component is the API Gateway. Attackers can exploit this through the API.
Recommendations Update NexusFlow API Gateway to version 3.8.1 or later.

Related Identifiers

CVE-2026-12345

Affected Products

Nexusflow Api Gateway