---
id: CVE-2026-34227
title: >-
  Sliver is a command and control framework that uses a custom Wireguard
  netstack
summary: >-
  Sliver is a command and control framework that uses a custom Wireguard
  netstack. Prior to version 1.7.4, a single click on a malicious link gives an
  unauthenticated attacker immediate, silent control over every active C2
  session or beaco…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
  - CWE-942
vendor: bishopfox
product: sliver
affected:
  - sliver < 1.7.4
patched:
  - sliver 1.7.4
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34227'
references:
  - url: >-
      https://github.com/BishopFox/sliver/security/advisories/GHSA-6fpf-248c-m7wm
    label: security-advisories@github.com
  - url: >-
      https://github.com/BishopFox/sliver/security/advisories/GHSA-6fpf-248c-m7wm
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.00469
epssPercentile: 0.37865
ingestedAt: '2026-07-24T20:38:02.415Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/skoveit/CVE-2026-34227'
  checkedAt: '2026-09-25T08:20:55.386Z'
exploitAvailable: true
---

## Overview

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.

## Affected

- `sliver < 1.7.4`

## Remediation

Upgrade past the affected range:

- `sliver 1.7.4`
