Tag

Path Traversal

All articles tagged with #path traversal

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products
security3 days ago

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products

Atlassian disclosed CVE-2026-21589 on October 5, a critical path traversal flaw affecting eight self-hosted Data Center products. The vulnerability allows unauthenticated attackers to read specific files in the web application root directory if they know the exact file path. Atlassian rated the flaw 9.3/10 on the CVSS scale. Cloud versions are already patched, but self-hosted users must upgrade to specific fixed versions or apply temporary mitigations. Atlassian has not confirmed active exploitation but advises users to check logs for suspicious requests.

WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw
cybersecurity15 days ago

WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw

Attackers began exploiting a critical WordPress vulnerability within hours of its disclosure, escalating from reconnaissance to active remote code execution attempts. The flaw, CVE-2026-87902, allows unauthenticated attackers to load arbitrary PHP files if specific theme and server conditions are met. WordPress released version 7.1.2 to fix the issue, urging immediate updates as exploitation attempts surged tenfold.

Attackers Exploit WordPress Path Traversal Flaw Within Hours of Patch Release
security16 days ago

Attackers Exploit WordPress Path Traversal Flaw Within Hours of Patch Release

WordPress released version 7.1.2 on September 22 to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability. The flaw allows attackers to load arbitrary PHP files, potentially leading to remote code execution on servers with specific configurations. Attackers began exploiting the vulnerability within hours of the patch, escalating from reconnaissance to writing malicious files. Site owners are urged to update immediately, as the fix is backported to all supported branches down to version 4.7.

CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706
security25 days ago

CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706

CISA warns that attackers are probing for and could exploit CVE-2026-85706, a maximum-severity GitLab path-traversal flaw that allows unauthenticated access to credentials via the repository commits API. GitLab fixed the issue in CE/EE versions 19.3.2, 19.2.6, and 19.1, and organizations are urged to patch immediately as in-the-wild probes have been observed and the flaw was added to the actively exploited catalog.

GitLab issues urgent patch for critical path-traversal flaw CVE-2026-85706
security28 days ago

GitLab issues urgent patch for critical path-traversal flaw CVE-2026-85706

GitLab urges self-hosted installations to patch CVE-2026-85706, a max-severity path traversal flaw in the repository-commits API that could allow unauthenticated access to arbitrary data; patches are available in GitLab CE/EE 19.3.2, 19.2.6, and 19.1, with GitLab.com already on patched code. WatchTowr reports in-the-wild probing for exploitation, and a related issue—CVE-2026-87719 (insecure deserialization in GraphQL subscriptions)—is also fixed in these versions. Admins should upgrade immediately to protect credentials and configs; GitLab serves millions of users, including Fortune 100 companies.

GitLab fixes critical path-traversal flaw after rapid in-the-wild probes
security28 days ago

GitLab fixes critical path-traversal flaw after rapid in-the-wild probes

GitLab released patches for a critical path-traversal flaw (CVE-2026-85706, CVSS 10) in the repository commits API that could let an unauthenticated attacker read arbitrary server files; in-the-wild probes were observed within hours of disclosure. The fixes also address a high-severity insecure deserialization issue in GitLab EE (CVE-2026-87719). Admins should upgrade to patched versions (CE/EE 19.1.8, 19.2.6, 19.3.2) or limit internet exposure, and monitor for suspicious POST requests to /api/v4/projects/{id}/repository/commits/ containing file.Path parameters to identify exploitation attempts.

Windmill path-traversal flaw exploited to read server files; patch issued
technology2 months ago

Windmill path-traversal flaw exploited to read server files; patch issued

A high-severity Windmill vulnerability, CVE-2026-29059, enables unauthenticated path traversal via the get_log_file endpoint to read arbitrary server files; if SUPERADMIN_SECRET is configured, the flaw could expose a Bearer-token for superadmin authentication and code execution, though default setups are limited to file reads. Windmill released a fix (1.603.3) in January 2026 by sanitizing the filename parameter. VulnCheck reports about 170 vulnerable systems across 24 countries and observed exploitation targeting Windmill endpoints and the Nextcloud proxy path. Separately, CISA’s KEV catalog highlights WP2Shell WordPress flaws and Langflow RCE vulnerabilities with widespread PoCs, urging WordPress users to update and noting a July 24, 2026 remediation deadline for Federal Civilian Executive Branch agencies.

Critical UniFi Flaws Allow Full System Takeover, Patch Now
cybersecurity6 months ago

Critical UniFi Flaws Allow Full System Takeover, Patch Now

Ubiquiti disclosed two critical-to-high vulnerabilities in UniFi Network Application: CVE-2026-22557, a path-traversal flaw that can allow unauthenticated attackers to seize full control of the underlying host, and CVE-2026-22558, an authenticated NoSQL injection enabling privilege escalation. Affected versions include UniFi Network App 10.1.85 and earlier, 10.2.93 and earlier, and UniFi Express Network App 9.0.114 and earlier. Patches are available: official 10.1.89+ (or RC 10.2.97+; UX 4.0.13+) bundling Network App 9.0.118+. Given the CVSS 10 rating for CVE-2026-22557, patch immediately and implement network segmentation/firewall controls for the UniFi management interface.

WinRAR ADS path-traversal flaw drives ongoing global intrusions
security8 months ago

WinRAR ADS path-traversal flaw drives ongoing global intrusions

Security researchers warn that WinRAR CVE-2025-8088, a high-severity path-traversal flaw abusing Alternate Data Streams to drop payloads, remains actively exploited by both state-backed groups and financially motivated criminals. The exploit chain hides malicious ADS inside decoy files and uses directory traversal to drop LNK/HTA/BAT/CMD payloads that execute on login. Actors such as RomCom/UNC4895, APT44, TEMP.Armageddon, Turla, and China-linked groups have used it for espionage and malware delivery, while criminals distribute RATs and info-stealers, with exploits marketed by underground actors. The activity underscores exploit commoditization and emphasizes the need to patch WinRAR promptly to mitigate ongoing risk.

Microsoft's AI Web Project Faces Security Flaws
technology1 year ago

Microsoft's AI Web Project Faces Security Flaws

Researchers discovered a critical security flaw in Microsoft's new NLWeb protocol, which allows remote reading of sensitive files, including API keys, due to a path traversal vulnerability. Microsoft patched the issue but has not issued a CVE, raising concerns about security oversight in AI-related protocols. The flaw could have severe consequences for AI agents relying on exposed API keys, emphasizing the need for careful security practices in deploying new AI features.

Microsoft Azure API Management Service Vulnerabilities Patched
api-management-vulnerability3 years ago

Microsoft Azure API Management Service Vulnerabilities Patched

Three new security flaws have been discovered in Microsoft Azure API Management service, including two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal. Exploitation of SSRF flaws can result in loss of confidentiality and integrity, permitting a threat actor to read internal Azure resources and execute unauthorized code. Following responsible disclosure, all the three flaws have been patched by Microsoft.