Angeet's vulnerability footprint centers on its ES3 KVM virtualization appliance and associated firmware, where disclosed issues recur around OS command injection and missing authentication for critical functions—typical weaknesses for embedded management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Angeet over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32298CRITICAL The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands. | Mar 17, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-32297HIGH The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system bina | Mar 17, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Angeet.
Media articles that mention a CVE ID that affects a product developed by Angeet — matched by CVE ID, not by vendor name.