CVE-2026-50743

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.


We have discovered 9,775 live websites that are affected by CVE-2026-50743.

Run a Free Instant Scan




Affected Software

Product  Revive Adserver
Category Advertising Networks
Vulnerable Domains9,775 live websites (100% of Revive Adserver install base)
Vulnerable Versions
  • from 0 through 6.0.7
Vulnerable Versions Count59 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jul 20, 2026
  • Updated - Jul 20, 2026

Credits

  • Althaf Shajahan (an_gr_y) (finder)

Website Distribution by Country

Number of websites using CVE-2026-50743
United States2,830 websites



Germany2,264 websites
Hungary640 websites
France475 websites
Poland373 websites
Russia211 websites
Portugal179 websites
Italy178 websites
GB172 websites
Spain154 websites

Website Distribution by TLD

Number of websites using CVE-2026-50743
.com3,119 websites
.de1,548 websites
.net592 websites
.pl358 websites
.org286 websites
.it161 websites
.com.br147 websites
.info143 websites
.ru137 websites
.nl118 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-50743

Top websites that are affected by CVE-2026-50743. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.jp Japan*,***
*.******.net United States*,***
***.****.******.jp Japan*,***
***********.ro Romania**,***
***********.com United States**,***
***.de Germany**,***
***************.nl Netherlands**,***
********.com United States**,***
***.se Sweden**,***
****.org Sweden**,***
See full domain list

FAQ

CVE-2026-50743 is Cross-Site Request Forgery (CSRF) in Revive Adserver
A total of 9,775 websites have been identified as vulnerable to CVE-2026-50743, based on global website indexing conducted by WebTechSurvey.
The Revive Adserver is affected by the CVE-2026-50743 vulnerability.
Revive Adserver versions up to and including 6.0.7 are vulnerable to CVE-2026-50743.