Unturned 3.26.3.5 closes a remote code execution exploit
The patch follows a report involving a malicious Workshop mod and temporarily affected Internet server listings.

Unturned version 3.26.3.5 is now available with a security fix for a remote code execution exploit tied to a malicious Workshop mod. The issue prompted the temporary removal of all Internet server listings while the patch was prepared and released, according to the official Steam announcement.
The developer said the known impact appeared limited to one small server. An anonymous player reported the exploit, while Jdance created a proof-of-concept test case after initially reporting it through the community Discord.
Daniel Willett also scanned Workshop uploads from the previous month to check for other instances of the exploit. The scan did not find evidence that it had been used elsewhere.
Patch Notes for Unturned 3.26.3.5
This is a focused security patch. Its sole listed fix blocks a Unity event setup that could be abused to call restricted methods, including Application.OpenURL.
Fixed
- Prevent loading components with UnityEvents connected to static methods. These could be exploited to call restricted methods such as Application.OpenURL. (By default, the game filters third-party URLs.)
With the exploit addressed, the temporary server-listing restriction was part of the precautionary response to the report rather than a broader gameplay change.
Share your thoughts on the security fix in the comments, and follow us on X, Bluesky, YouTube, and Instagram.
Unturned
Developed by Nelson Sexton, Smartly Dressed Games





