KAMSOFT KS-SOMED hardcoded FTP creds flaw
Hardcoded credentials in KAMSOFT KS-SOMED medical software exposed an update FTP server, risking malicious update distribution to clients.
CERT Polska coordinated disclosure of CVE-2026-42251, a vulnerability in KAMSOFT KS-SOMED, a Polish healthcare management software suite. The flaw stemmed from hard-coded credentials embedded in the KSPLUPDFTP.exe and ANEKSKLIENT.EXE update modules, which granted access to the FTP server hosting official software update packages. An attacker in possession of these credentials could have uploaded a malicious update file that would then be distributed and installed on client machines as though it were a legitimate vendor update, effectively enabling a software supply-chain compromise against KS-SOMED users.
The issue affects KSPLUPDFTP.exe versions up to 30.00.00.056 and ANEKSKLIENT.EXE versions up to 29.00.02.026. KAMSOFT has since removed the hard-coded credentials from the codebase, restructured the update process, and restricted the access previously granted by the exposed credentials to read-only. There is no indication in the report that the vulnerability was actively exploited; it was responsibly disclosed by researcher Wojciech Giełda and remediated through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-42251
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free