External risk intelligence

FatPipe MPVPN Buffer Overflow Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90823

The vulnerability affects network appliances commonly deployed at the network edge. While the management interface is disabled by default, these devices are designed to act as gateways, and management interfaces are frequently exposed to the internet or wide-area networks in real-world deployment scenarios.

Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in FatPipe network appliances that, if exploited, could allow unauthorized code execution. While the affected management interface is disabled by default, its potential exposure warrants attention to confirm relevance and exposure to our environment.

  • Unauthenticated attackers could run unauthorized code.
  • Critical vulnerability in network appliances.
  • Confirm relevance and exposure; assess impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker could reach an affected appliance, provided its management interface was enabled, and send a specially crafted request. This request would target a flaw in the authentication process, potentially leading to arbitrary code execution with high privileges.

  • Attack requires enabled management interface.
  • Malicious authentication request triggers overflow.
  • Arbitrary code execution as root is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as root on affected FatPipe appliances. This is possible when the management interface, which is disabled by default, is enabled and exposed to the network. Such an exposure could occur when these appliances are used as internet gateways or when management access is not properly restricted.

  • Asset at risk: Appliance root access and network control.
  • How exposure could happen: Malicious input to enabled management interface.
  • Realistic consequence: Unauthorized control over network traffic.

Operational Fix

Recommended remediation, mitigation, and detection steps

Infrastructure and network security teams are likely responsible for addressing this vulnerability in FatPipe appliances. The first practical step is to identify all instances of the affected technology, confirm if the management interface is enabled and exposed, and then determine business criticality before coordinating with the vendor for remediation.

  • Infrastructure and Security teams own this.
  • Verify management interface exposure.
  • Coordinate with FatPipe for upgrade.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FatPipe MPVPN, WARP, and IPVPN?

These are specialized network appliances designed to manage WAN connectivity and provide secure site-to-site communication. They typically sit at the network edge to aggregate multiple connections, ensuring reliable and optimized data transit for enterprise environments.

What does CVE-2026-90823 mean for system security?

This vulnerability is a stack-based buffer overflow, categorized as CWE-121. It occurs when the software receives more data than its memory buffer can hold, causing it to overwrite adjacent memory. In this case, an attacker can leverage this flaw to run unauthorized code with root-level privileges.

How is the buffer overflow triggered in this vulnerability?

An attacker triggers the flaw by sending a specially crafted authentication request to the appliance's management interface. If the management interface is disabled—which is the default configuration—the request cannot reach the vulnerable code, meaning the bug remains inactive.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal notes that while the management interface is disabled by default, these appliances often act as internet-facing gateways. If your management interface has been affirmatively enabled and is reachable from the internet or a wide-area network, your device faces a higher risk of exploitation.

Do I need to update my FatPipe firmware?

Yes, if you are running version 10.1.2r60p100, you are using end-of-life firmware. Your first step should be to verify the appliance's management settings and restrict access to trusted networks. Then, contact FatPipe support to coordinate the transition to a currently supported release.

References