Impact
Low
CVE
CVE-2026-43499
Version(s)
4.x
First published
Last updated

GhostLock 

We are aware of the recent Local Privilege Escalations (LPEs) exploit GhostLock. 

It is important to note that this exploit requires local access to a system to be exploited, something that would require an issue with the running micro-services or associated services to have been exposed and exploited in the first instance.

At the time of writing Red Hat have not released an upstream patch or fix, so current advice to customers to ensure the security of their system is to prevent untrusted actors or unauthorised users from accessing the VQ Conference Manager in the first instance. Customers with externally exposed SSH or admin portals instances will be most at risk. 

Customers who are concerned about this issue are advised to get in contact via support@vqcomms.com

VQ Communications Secures Milestone U.S. Army Agreement for Sovereign Collaboration

  • News

VQ’s Monthly News – June 2026

  • News

VQ’s Monthly News – May 2026

  • News