THREAT OPS › Threat News › [NVD] CVE-2026-25551 (HIGH 7.8) — Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, lim
[NVD] CVE-2026-25551 (HIGH 7.8) — Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, lim
CVE-2026-25551 CVSS: 7.8 HIGH Published: 2026-06-04T18:16:28.923
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, limiting the attack surface to local access only. The end
Indicators of compromise
- CVE-2026-25551cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-25551