Topic
Path Traversal
9 reports tagged Path Traversal, spanning news and vulnerability coverage.
Articles tagged Path Traversal
-
NewsExploited FortiMail flaw lets attackers write files with no fix out yet
CISA added an unauthenticated FortiMail path traversal to its KEV catalog with a three-day deadline and a compromise check, while fixed builds are still pending.
-
Vulnerability2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102)
Two CVSS 9.8 Check Point flaws, a VPN-negotiation RCE in Quantum Security Gateway and a pre-auth upload bug in Management, were CISA KEV-listed September 22.
-
VulnerabilityDify Path Traversal (CVE-2026-41948)
CVE-2026-41948 is a CVSS 9.4 path traversal flaw in Dify allowing cross-tenant access to internal debug endpoints, reported exploited by VulnCheck.
-
VulnerabilityRed Hat OpenShift AI— Feast Feature Server Path Traversal (CVE-2026-23536)
CVE-2026-23536 is a CVSS 7.5 unauthenticated path traversal in the Feast Feature Server shipped with Red Hat OpenShift AI.
-
VulnerabilityJFrog Artifactory Path Traversal (CVE-2026-66384)
CVE-2026-66384 is a CVSS 5.3 path traversal in JFrog Artifactory affecting the Docker cache, confirmed exploited per CISA KEV.
-
Vulnerabilityknowns Path Traversal (CVE-2026-86538)
CVE-2026-86538 is a CVSS 7.5 unauthenticated path traversal in the knowns application, reported exploited by VulnCheck alone.
-
VulnerabilityMLflow Path Traversal (CVE-2026-2614)
CVE-2026-2614 is a CVSS 7.5 unauthenticated path traversal in MLflow model registry, reported exploited by VulnCheck alone.
-
VulnerabilityVite Path Traversal (CVE-2026-39364)
CVE-2026-39364 is a CVSS 7.5 file-restriction bypass in the Vite dev server, reported exploited by VulnCheck alone.
-
VulnerabilityGitLab Community Edition Path Traversal (CVE-2026-85706)
CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw in GitLab CE/EE, added to CISA's KEV catalog on September 11, 2026 as actively exploited.