Tag

Path Traversal

All articles tagged with #path traversal

Windmill path-traversal flaw exploited to read server files; patch issued
technology1 month ago

Windmill path-traversal flaw exploited to read server files; patch issued

A high-severity Windmill vulnerability, CVE-2026-29059, enables unauthenticated path traversal via the get_log_file endpoint to read arbitrary server files; if SUPERADMIN_SECRET is configured, the flaw could expose a Bearer-token for superadmin authentication and code execution, though default setups are limited to file reads. Windmill released a fix (1.603.3) in January 2026 by sanitizing the filename parameter. VulnCheck reports about 170 vulnerable systems across 24 countries and observed exploitation targeting Windmill endpoints and the Nextcloud proxy path. Separately, CISA’s KEV catalog highlights WP2Shell WordPress flaws and Langflow RCE vulnerabilities with widespread PoCs, urging WordPress users to update and noting a July 24, 2026 remediation deadline for Federal Civilian Executive Branch agencies.

Critical UniFi Flaws Allow Full System Takeover, Patch Now
cybersecurity5 months ago

Critical UniFi Flaws Allow Full System Takeover, Patch Now

Ubiquiti disclosed two critical-to-high vulnerabilities in UniFi Network Application: CVE-2026-22557, a path-traversal flaw that can allow unauthenticated attackers to seize full control of the underlying host, and CVE-2026-22558, an authenticated NoSQL injection enabling privilege escalation. Affected versions include UniFi Network App 10.1.85 and earlier, 10.2.93 and earlier, and UniFi Express Network App 9.0.114 and earlier. Patches are available: official 10.1.89+ (or RC 10.2.97+; UX 4.0.13+) bundling Network App 9.0.118+. Given the CVSS 10 rating for CVE-2026-22557, patch immediately and implement network segmentation/firewall controls for the UniFi management interface.

WinRAR ADS path-traversal flaw drives ongoing global intrusions
security7 months ago

WinRAR ADS path-traversal flaw drives ongoing global intrusions

Security researchers warn that WinRAR CVE-2025-8088, a high-severity path-traversal flaw abusing Alternate Data Streams to drop payloads, remains actively exploited by both state-backed groups and financially motivated criminals. The exploit chain hides malicious ADS inside decoy files and uses directory traversal to drop LNK/HTA/BAT/CMD payloads that execute on login. Actors such as RomCom/UNC4895, APT44, TEMP.Armageddon, Turla, and China-linked groups have used it for espionage and malware delivery, while criminals distribute RATs and info-stealers, with exploits marketed by underground actors. The activity underscores exploit commoditization and emphasizes the need to patch WinRAR promptly to mitigate ongoing risk.

Microsoft's AI Web Project Faces Security Flaws
technology1 year ago

Microsoft's AI Web Project Faces Security Flaws

Researchers discovered a critical security flaw in Microsoft's new NLWeb protocol, which allows remote reading of sensitive files, including API keys, due to a path traversal vulnerability. Microsoft patched the issue but has not issued a CVE, raising concerns about security oversight in AI-related protocols. The flaw could have severe consequences for AI agents relying on exposed API keys, emphasizing the need for careful security practices in deploying new AI features.

Microsoft Azure API Management Service Vulnerabilities Patched
api-management-vulnerability3 years ago

Microsoft Azure API Management Service Vulnerabilities Patched

Three new security flaws have been discovered in Microsoft Azure API Management service, including two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal. Exploitation of SSRF flaws can result in loss of confidentiality and integrity, permitting a threat actor to read internal Azure resources and execute unauthorized code. Following responsible disclosure, all the three flaws have been patched by Microsoft.