CVE Intel / CVE-2026-46339

CVE-2026-46339

unknown · unknown
⚠
Actively exploited in the wild. Exploitation attempts against this CVE have been captured on the huntback sensor network.
exploited on our sensorsCritical network detectable

What it is

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.

Live exploitation on the huntback network (30 days)

365
attempts captured
315
distinct source IPs
2026-10-07
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.

How huntback helps

Deploy a decoy that emulates unknown and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.

CVSSn/a Critical
EPSS0.03 (3% pct)
In CISA KEVno
Publishedn/a
Network detectableyes, signatured
Public exploitnone known