< ciso
brief />
Tag Banner

All news with #path traversal tag

62 articles

Critical Atlassian Data Center Path Traversal Fixes

🔒 Atlassian disclosed CVE-2026-21589, a critical path traversal vulnerability in eight Data Center products that allows unauthenticated attackers who know a file's exact path to read files from the web application root. The flaw, rated 9.3 CVSS v4.0, affects on-premises deployments and has fixed versions listed for each product; cloud offerings have been patched. Atlassian advises offlineing or restricting internet access for instances that cannot be upgraded and provides temporary WAF or server-level blocking rules as mitigations.
read more →

Critical Dell DSU Flaw Lets Attackers Gain Root

🛡️ Dell warned customers to update the System Update (DSU) CLI after a critical path traversal vulnerability (CVE-2026-86360) was disclosed that can allow unauthenticated attackers to execute code with root privileges. The company released DSU 2.3.0.0 to patch this and four other high-severity issues, and urged immediate upgrades. U.S. agencies previously warned vendors to eliminate path traversal weaknesses, and organizations should patch promptly to reduce risk.
read more →

Critical FortiMail Path Traversal Zero‑Day Alert

🔒 The U.S. CISA has added a critical Fortinet FortiMail flaw (CVE-2026-104286, CVSS 9.8) to its KEV catalog after reports of active exploitation. The vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests due to path traversal and NULL byte handling issues. Fortinet has identified affected FortiMail versions and provided upgrade guidance and temporary workarounds, including disabling IBE and restricting management access.
read more →

Kiteworks fixes max-severity EPG code-injection flaw

🔒 Kiteworks released security updates addressing 126 vulnerabilities across its platform, including a max-severity code-injection flaw in the Email Protection Gateway (EPG). The issue, tracked as CVE-2026-54154, was reported via the YesWeHack bug bounty program and allowed unauthenticated remote code execution through a chain of path traversal, code injection, and missing authentication. The EPG flaw affects versions prior to 9.4.1 and is patched in 9.4.1 or later, while additional critical issues in Core and EPG were also fixed.
read more →

TeamViewer urges immediate patch for severe flaws

🔒 TeamViewer has issued an urgent advisory urging customers to update immediately after disclosing multiple high-severity vulnerabilities in its Full Client and Host software for Windows, macOS, and Linux. The most critical issue is a remote session access control bypass (CVE-2026-92370) that could allow unauthorized remote actions leading to remote code execution. Four other flaws include path traversal, heap overflow, TOCTOU race condition, and improper path validation, which can enable local or remote code execution and privilege escalation. TeamViewer recommends upgrading to version 15.82, noting no evidence of public exploits or active in-the-wild abuse so far.
read more →

CISA Adds Critical WSO2 and Adobe Flaws to KEV

🔒 CISA has added two critical vulnerabilities—affecting WSO2 and Adobe Commerce/Magento—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws include a path traversal and unrestricted file upload in WSO2 leading to remote code execution, and an authorization bypass in Adobe Commerce that allows customer account takeover. Federal agencies are advised to patch by September 27, 2026.
read more →

Critical WordPress flaw exploited for remote code execution

🔍 Threat actors have progressed from scanning for CVE-2026-87902 to actively exploiting the vulnerability to write files that execute shell commands when accessed. Patchstack observed initial reconnaissance less than five hours after WordPress 7.1.2 was released, with malicious activity increasing tenfold as attackers began delivering payloads. The flaw, discovered by Robert Ressl, is an unauthenticated path traversal that can lead to RCE under specific theme and server conditions. Administrators are urged to update to WordPress 7.1.2 and review logs for indicators of compromise.
read more →

Check Point issues hotfix for critical management server zero‑day

🛡️ Check Point Software issued emergency hotfixes for a critical Security Management Server vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts via a path traversal flaw tracked as CVE-2026-93616. The company confirmed active exploitation against a small number of customers and published indicators of compromise and temporary mitigations for those who cannot immediately patch. The fix is included in the R82.20 Security Hotfix and applies to Management, Log, Multi‑Domain, and SmartEvent products.
read more →

Maximum-severity GitLab flaw risks CI/CD trust

🚨 GitLab disclosed CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that can allow unauthenticated attackers to read arbitrary files with a single HTTP request. The bug affected Community and Enterprise editions and has been patched; GitLab urged self-hosted, public-facing instances to patch immediately or remove access. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and threat intel already reports in-the-wild probes. Experts warn this poses broad risk because GitLab often links to build, deployment, and secret-bearing files.
read more →

Urgent Patch for GitLab Path Traversal Flaw

🛡️ GitLab has released a fix for a maximum-severity path traversal vulnerability (CVE-2026-85706) that allowed unauthenticated users to read arbitrary files via the repository commits API. The issue affects multiple versions and was remediated on September 10. Security vendors reported in-the-wild probes shortly after disclosure, and CISA added the flaw to its KEV Catalog, urging rapid remediation. Organizations are advised to patch immediately and hunt logs for suspicious POST requests to the commits endpoint.
read more →

Critical GitLab path traversal flaw draws rapid probes

🔒 GitLab released emergency patches to fix multiple vulnerabilities, including CVE-2026-85706, a CVSS 10.0 path traversal bug in the repository commits API that can let unauthenticated actors read arbitrary files under certain conditions. The flaw affects several CE and EE releases prior to the 19.3.2, 19.2.6 and 19.1.8 fixes, and was observed being probed in the wild from 06:00 UTC on September 11, 2026. GitLab also patched an insecure deserialization issue in EE (CVE-2026-87719, CVSS 9.9). Organizations running internet-exposed, self-managed instances are urged to apply patches immediately or restrict public access.
read more →

GitLab urges immediate patch for critical path flaw

🚨 GitLab has released urgent updates to address a maximum-severity path traversal vulnerability (CVE-2026-85706) discovered in the repository commits API and reported via HackerOne. The flaw allows unauthenticated attackers, under certain conditions, to read arbitrary files from vulnerable servers, potentially exposing credentials and secrets. GitLab patched this and a separate critical insecure deserialization bug (CVE-2026-87719) and strongly urges self-managed instances to upgrade to the fixed CE/EE releases immediately.
read more →

AIT-GUI flaws could let unauthenticated actors command craft

🔒 Security researchers at Cycode disclosed a critical chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, allowing unauthenticated attackers to issue arbitrary commands to the instrument and spacecraft command bus. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 (CVSS v3.1), the issues affect AIT-GUI ≤2.5.1 and were addressed in 2.5.2 on August 12, 2026. The defects include missing authentication, absent CSRF protection, and path traversal on state-changing routes, enabling POST-based command, script execution, and sequence abuse when reachable.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Zoom patches zero-click RCE and VDI disclosure flaws

🛡️ Zoom has patched four vulnerabilities across its applications, including two zero-click remote code execution issues that allow a meeting participant to execute malicious code on other attendees' systems without any interaction. Three client vulnerabilities affect Zoom versions before 7.1.5 and 7.0.6 and stem from memory corruption in the text annotation feature; a fourth path traversal flaw impacts Zoom Workplace VDI Client and plugins before 7.0.11 and 6.6.15. The annotation bugs were found by A Security using an AI agent, which built a working exploit in under 24 hours, and Zoom has provided mitigations including server-side filtering and guidance to restrict optional features and enforce client version minimums.
read more →

Active exploitation of Windmill path traversal bug

🛡️ A high-severity path traversal flaw in open-source developer platform Windmill (CVE-2026-29059, CVSS 7.5) has been observed exploited in the wild to read arbitrary files via the get_log_file endpoint. The issue allowed attackers to access sensitive files such as /etc/passwd and, where configured, the SUPERADMIN_SECRET value, enabling superadmin access. Windmill patched the vulnerability in version 1.603.3 by adding filename sanitization; about 170 vulnerable systems across 24 countries were identified.
read more →

Progress restores ShareFile after security suspension

🔒 Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension following the detection of a credible external security threat on July 10. The incident involved exploitation of a high-severity path traversal vulnerability in Storage Zones Controller versions 5.x and 6.x, and patched releases 5.12.5 and 6.0.2 have been issued. Progress reported no evidence of unauthorized access and is withholding the CVE to allow customers time to patch.
read more →

Progress confirms ShareFile zero‑day behind shutdown

🛡️ Progress Software confirmed a high‑severity zero‑day in ShareFile Storage Zone Controller that prompted an emergency shutdown of customer Windows servers. The flaw is a path traversal impacting all 5.x and 6.x releases, allowing an authenticated admin to read arbitrary files, write attacker‑controlled content, or enumerate the filesystem. Progress released patches (5.12.5 and 6.0.2), reserved a CVE to be published in two weeks, and currently reports no evidence of customer data breaches.
read more →

CISA Adds Four Newly Exploited Vulnerabilities

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaws include critical Adobe ColdFusion path traversal (CVE-2026-48282), Joomlack Page Builder improper access control (CVE-2026-56290), Langflow authorization bypass (CVE-2026-55255), and JoomShaper SP Page Builder unrestricted file upload (CVE-2026-48908). Exploitation observed ranged from immediate post-disclosure attacks to targeted campaigns stealing credentials and deploying web shells. Agencies are urged to apply patches by July 10, 2026.
read more →

DifyTap vulnerabilities expose cross-tenant AI data

🛡️ Cybersecurity researchers disclosed four vulnerabilities in Dify, an open-source agentic workflow platform, that could let attackers read AI conversations across tenants without authentication. Codenamed DifyTap by Zafran Security, two flaws are critical and three enable cross-tenant impact on Dify's multi-tenant cloud service. Issues include authorization bypasses, path traversal to internal Plugin Daemon APIs, and file preview leaks. Patches were released in v1.14.2 for all but one flaw, with the remaining fix forthcoming.
read more →