CVE-2026-27971 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 5, 2026
Qwik - Remote Code Execution
Overview
Qwik <=1.19.0 contains an insecure deserialization vulnerability in the server$ RPC mechanism, letting unauthenticated attackers execute arbitrary code remotely, exploit requires require() availability at runtime.
Severity & Score
Impact
Unauthenticated attackers can execute arbitrary code on the server, leading to full system compromise.
Mitigation
Update to version 1.19.1 or later.
Social Media Activity(1 post)
📈 CVE Published in last 30 days (2026-03-02 - 2026-04-01) See more at https://secdb.nttzen.cloud/dashboard Total CVEs: 6145 Severity: - Critical: 615 - High: 2408 - Medium: 2575 - Low: 237 - None: 310 Status: - : 52 - Analyzed: 2872 - Awaiting Analysis: 2622 - Modified: 245 - Received: 185 - Rejected: 58 - Undergoing Analysis: 111 Top CNAs: - GitHub, Inc.: 1471 - Patchstack: 699 - VulnCheck: 594 - VulDB: 577 - MITRE: 381 - Wordfence: 308 - kernel.org: 180 - Microsoft Corporation: 97 - Apple Inc.: 89 - Adobe Systems Incorporated: 86 Top Affected Products: - UNKNOWN: 3040 - Openclaw: 173 - Google Android: 101 - Apple Macos: 79 - Google Chrome: 75 - Wwbn Avideo: 65 - Parseplatform Parse-server: 56 - Mozilla Firefox: 48 - Apple Ipados: 44 - Open-emr Openemr: 44 Top EPSS Score: - CVE-2025-14558 - 53.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2025-14558) - CVE-2026-29058 - 42.99 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-29058) - CVE-2026-1492 - 29.00 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-1492) - CVE-2026-2025 - 26.43 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2025) - CVE-2026-2413 - 26.22 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2413) - CVE-2026-27971 - 23.12 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27971) - CVE-2023-7337 - 22.17 % (https://secdb.nttzen.cloud/cve/detail/CVE-2023-7337) - CVE-2026-33634 - 20.84 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-33634) - CVE-2026-2493 - 15.24 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-2493) - CVE-2025-71260 - 9.15 % (https://secdb.nttzen.cloud/cve/detail/CVE-2025-71260)
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27971
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- insecure_deserialization
- Status
- confirmed
- EPSS
- 2311.8%
- Nuclei
- Available
- Social Posts
- 1
CWE
- CWE-502
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H