< ciso
brief />
Tag Banner

All news with #arbitrary file write tag

25 articles

Critical FortiMail Path Traversal Zero‑Day Alert

🔒 The U.S. CISA has added a critical Fortinet FortiMail flaw (CVE-2026-104286, CVSS 9.8) to its KEV catalog after reports of active exploitation. The vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests due to path traversal and NULL byte handling issues. Fortinet has identified affected FortiMail versions and provided upgrade guidance and temporary workarounds, including disabling IBE and restricting management access.
read more →

Critical FortiMail Zero-Day Allows Remote Code Execution

🚨 Fortinet warns of a critical FortiMail vulnerability (CVE-2026-104286) actively exploited in zero-day attacks that can allow unauthenticated attackers to write arbitrary files and execute code via crafted HTTP/HTTPS requests. The flaw affects multiple FortiMail 7.x and 8.0 releases; Fortinet identified the issue internally and provided temporary workarounds while patches are prepared. Admins are urged to disable IBE support or block management access from the Internet and to check published IOCs and logs for signs of compromise.
read more →

Critical RCE Flaw Exploited in WooCommerce Plugin

🔒 Wordfence has observed active exploitation of a critical vulnerability (CVE-2026-27540) in the premium WordPress plugin WooCommerce Wholesale Lead Capture, enabling unauthenticated attackers to upload arbitrary files and achieve remote code execution. The flaw affects versions up to 2.0.3.1 and has prompted over 100,000 blocked exploit attempts since June 2026. Site owners should inspect for unexpected .php files and suspicious admin-ajax requests referencing the "wwlc_file_upload_handler" action.
read more →

Critical WooCommerce Plugin Flaw Enables PHP Webshells

🔒 Hackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin (CVE-2026-27540) to upload PHP webshells and execute code on affected WordPress sites. The unauthenticated arbitrary file-upload flaw affects versions 2.0.3.1 and older and was fixed in version 2.0.3.2 released February 20. Wordfence blocked over 100,000 related attacks and urges administrators to update, scan for unexpected PHP files, check logs for wwlc_file_upload_handler requests, and restore from clean backups if compromised.
read more →

Critical Elementor Pro file upload flaw allows RCE

🛡️ Cybersecurity researchers disclosed a critical vulnerability in the Elementor Pro WordPress plugin that permits unrestricted upload of dangerous file types, tracked as CVE-2026-32475 with a CVSS score of 9.0. The issue stems from the Forms module's File Upload field where extension checks and file-move operations run in separate loops, enabling unauthenticated attackers to bypass the extension blocklist by submitting duplicate file parts and write PHP files into wp-content/uploads/elementor/forms. The flaw affects versions up to 4.2.1 and was patched in 4.2.2 on August 19 after disclosure.
read more →

Critical Forminator flaw lets attackers execute code

🛡️ A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin — used on 600,000+ sites — allows unauthenticated attackers to upload arbitrary files, including executable PHP, and achieve remote code execution. The flaw, present in versions up to 1.56.1, stems from improper file type validation in the handle_file_upload() function and misuse of MIME key matching combined with a public submission handler. Patch 1.56.2, released on July 31, 2026, fixes the issue; site owners should update immediately.
read more →

High-severity flaws bypass Hugging Face diffusers trust check

🔒 Three high-severity vulnerabilities in Hugging Face’s diffusers library allowed crafted model repositories to execute arbitrary code during model loading by bypassing the trust_remote_code safeguard. Zafran Security published findings showing the trust check ran separately from the code load, creating timing and path-based bypasses exploited by crafted files and configuration changes. Hugging Face patched the issues in diffusers 0.38.0 in May and acknowledged related concerns in transformers.
read more →

CISA warns of exploited RCE in Joomla extensions

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting arbitrary file upload vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution. The agency designated these flaws as maximum priority and ordered federal agencies to apply updates or mitigations within three days. Vendors released fixes in iCagenda 4.0.8/3.9.15 and Balbooa Forms 2.4.1 after automated and zero-day exploitation was observed. Administrators should check installations and apply the available patches immediately.
read more →

GhostApproval symlink flaw lets agents overwrite files

🛡️ Researchers at Wiz disclosed GhostApproval, a symlink-based flaw in six AI coding assistants that can trick an approval prompt into writing to sensitive files. The attack uses a repository with a symlink pointing to targets like ~/.ssh/authorized_keys or ~/.zshrc; the assistant asks to edit an innocuous file but writes to the real destination. Three tools have fixes, two are still unpatched, and Anthropic disputes the classification as a bug.
read more →

Cisco SD‑WAN flaw highlights management‑plane risk

🔒 Cisco has issued patches for a vulnerability in Cisco Catalyst SD‑WAN Manager that allowed authenticated users with write access to create or overwrite files via a flawed file upload API, potentially enabling later privilege escalation to root. The flaw, tracked as CVE‑2026‑20262, affected all deployment types and had been subject to limited exploitation; Cisco advised upgrading to fixed releases and reviewing logs for suspicious uploads such as index.jsp and .war files. Analysts warn that compromise of the management plane can lead to network‑wide control‑plane impact and recommend isolating, hardening, and tightly monitoring SD‑WAN managers as Tier‑0 assets.
read more →

Cisco issues patches for SD‑WAN file upload flaw

🔒 Cisco has released updates fixing a medium‑severity flaw in Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20262) that is being actively exploited. The bug allows an authenticated attacker with write access to create or overwrite files via a vulnerable web UI file upload API, which can be leveraged to escalate privileges. Affected on‑prem and cloud SD‑WAN deployments have fixes available across multiple release tracks; customers are urged to apply patches and audit logs for suspicious WAR uploads.
read more →

Path traversal in Langflow exploited to write files

🛡️ A high-severity path traversal flaw (CVE-2026-5027) in the AI development platform Langflow is being actively exploited to write arbitrary files to exposed servers. Tenable discovered the issue, which stems from unsanitized filenames in the POST /api/v2/files endpoint, and disclosed it on March 27, 2026. Patches were released in langflow-base 0.8.3 and Langflow 1.9.0, and users are urged to upgrade to version 1.10.0.
read more →

Critical Everest Forms Pro Flaw Lets Site Takeover

⚠️ A critical vulnerability (CVE-2026-3300) in Everest Forms Pro versions 1.9.12 and earlier allows unauthenticated attackers to execute arbitrary PHP on affected WordPress sites via the plugin's Complex Calculation feature. The issue stems from user-supplied values being inserted into an eval() string without properly escaping single quotes, enabling code injection. Wordfence telemetry shows active exploitation creating rogue administrator accounts, and a patch was issued by the developer on March 18.
read more →

Siemens ROS# Path Traversal Vulnerability — Update to 2.2.2

🔒 A path traversal flaw exists in the ROS# file_server prior to 2.2.2, allowing attackers to read and write arbitrary files accessible to the account running the service. The issue arises from improper input sanitization and is tracked as CWE-23 with a CVSS v3 score of 9.1. Siemens released 2.2.2 as the vendor fix and recommends immediate updates. Temporary mitigations include running the service only on trusted networks and with restricted user rights.
read more →

Critical file upload flaw exploited in Breeze Cache

⚠️ Researchers warn that a critical vulnerability (CVE-2026-3844) in the Breeze Cache WordPress plugin allows unauthenticated attackers to upload arbitrary files via the fetch_gravatar_from_remote function. Exploitation can lead to remote code execution and complete site takeover, but successful attacks require the optional 'Host Files Locally - Gravatars' add-on to be enabled. Cloudways released a patch in version 2.4.5; administrators should update immediately or disable the add-on until patched.
read more →

GIGABYTE Control Center has critical file-write flaw

⚠️ The GIGABYTE Control Center contains a critical arbitrary file-write vulnerability (CVE-2026-4415) affecting versions 25.07.21.01 and earlier when the pairing feature is enabled. Taiwan's CERT warns unauthenticated remote attackers could write files anywhere on the underlying OS, enabling arbitrary code execution, privilege escalation, or denial-of-service. GIGABYTE released version 25.12.10.01 with fixes for download path management, message processing, and command encryption and strongly advises immediate upgrade; users should obtain installers only from the vendor portal to avoid trojanized packages.
read more →

Unauthenticated File-Upload Flaw in Ceragon Siklu Devices

⚠️ A vulnerability in Ceragon / Siklu EtherHaul and MultiHaul microwave antennas allows unauthenticated uploads to any writable path via the rfpiped service on TCP port 555. File metadata uses weak encryption while file contents are transmitted in cleartext, and no authentication or path validation is performed. The issue is tracked as CVE-2025-57176 with a CVSS v3.1 base score of 5.3. Vendor firmware updates are available and should be applied promptly.
read more →

Cisco Flags More Catalyst SD-WAN Flaws as Actively Exploited

🔔 Cisco has warned that two additional Catalyst SD-WAN Manager vulnerabilities — a high-severity arbitrary file overwrite (CVE-2026-20122) and a medium-severity information disclosure flaw (CVE-2026-20128) — are being actively exploited. The file-overwrite vulnerability can be triggered remotely by attackers with valid read-only API credentials; the information-disclosure issue requires local vManage credentials. Cisco says the flaws affect the software regardless of device configuration and urges administrators to upgrade to fixed releases immediately.
read more →

RealHomes CRM Plugin Flaw Patched After Site Takeovers

⚠️ A critical flaw in the RealHomes CRM WordPress plugin—bundled with the widely used RealHomes theme and present on more than 30,000 sites—allowed any logged-in user with Subscriber access or higher to upload arbitrary files via a CSV import. Assigned CVE-2025-67968, the bug affected versions 1.0.0 and earlier and could lead to full site takeover. Developers released v1.0.1, adding a current_user_can check and file-type validation via wp_check_filetype; users should update immediately.
read more →

Critical AdonisJS bodyparser Path Traversal Risks File Write

🚨 Maintainers of @adonisjs/bodyparser urge immediate updates after disclosure of CVE-2026-21440, a critical path traversal flaw that can enable attackers to write arbitrary files via unsanitized multipart filenames. The vulnerability stems from MultipartFile.move(location, options) defaulting to client-supplied names when the options.name is omitted. Exploitation requires a reachable upload endpoint and can lead to file overwrite and possible RCE depending on deployment, filesystem permissions, and overwrite settings.
read more →