#pathtraversal
Pre-auth path traversal lets attackers load arbitrary Java code on Check Point's own management servers. https://intel.threadlinqs.com/threat/TL-2026-2617 #ThreatIntel #CVE_2026_93616 #CheckPoint #PathTraversal
September 22, 2026 at 5:07 PM
The vulnerability is by design: how an attack exploited an unknown feature of the standard library

ivan.canet.dev/blog/2024/09...

#programming #pathtraversal #infosec #webdev
The vulnerability is by design - Ivan “CLOVIS” Canet
Software engineering, open source and computer security
ivan.canet.dev
December 14, 2024 at 12:38 PM
I had missed this #linux #kernel discussion about #pathtraversal #vulnerabilities

[RFC] Add a prctl to disable ".." traversal in path resolution

https://lore.kernel.org/linux-fsdevel/20241211142929.247692-1-mjg59@srcf.ucam.org/T/#u
August 28, 2025 at 9:08 AM
🔴 CRITICAL Path Traversal Bug Hits Kentico!

A 9.0 CVSS vulnerability just hit Kentico Xperience!

https://www.youtube.com/shorts/DKGuuh-ObSc

#cybersecurity #vulnerability #kentico #pathtraversal #infosec
April 22, 2026 at 2:46 PM
🚨 CVE-2025-15036 (CRITICAL 9.6)

MLflow archive extraction flaw allows attackers to overwrite arbitrary files via path traversal (“../”) in tar.gz files, potentially leading to privilege escalation and sandbox escape.

🔎 basefortify.eu/cve_reports/...

#CVE #CyberSecurity #MLflow #PathTraversal
March 30, 2026 at 7:55 AM
Dieci bug gravi aggiornati in WordPress: Le scansioni stanno iniziando: aggiorna subito!

📌 Link all'articolo : www.redhotcyber.com/post/die...

#redhotcyber #news #wordpress #aggiornamento #vulnerabilita #cybersecurity #hacking #cms #pathtraversal
March 12, 2026 at 6:47 AM
DIVD is an official #CVE Numbering Authority & has uncovered critical flaws like:
🔹 #Mennekes EV chargers (#SQLinjection & #CommandInjection)
🔹 #Enphase IQ Gateway (#PathTraversal & #RemoteCodeExecution)

Their work helps tools like #BaseFortify stay ahead of threats.
March 20, 2025 at 12:42 PM
Mito: validar rutas es solo chequear el string. Real: se normaliza a forma canónica, se resuelven symlinks y si el Policy Engine no está seguro, deniega por default. #infosec #pathtraversal #linux
September 17, 2026 at 9:35 PM
⚠️ HIGH-severity vuln in Ai3 QbiCRMGateway 7.5.1: CVE-2025-9639 allows unauth'd file reads via path traversal. No patch—restrict access, monitor activity. More info: https://radar.offseq.com/threat/cve-2025-9639-cwe-23-relative-path-traversal-in-ai-dfeeca8d #OffSeq #Vulnerability #PathTraversal
August 29, 2025 at 9:02 AM
I analyzed three months of data from path-traversal attacks against SolarWinds Serv-U and wrote up my findings. Check it out on the @GreyNoise Grimoire!

#Cybersecurity #Blog #PathTraversal #Exploit
GreyNoise Labs - Whatchu looking for (starring SolarWinds Serv-U - CVE-2024-28995)
SolarWinds Serv-U has given us a really good dataset for which files attackers are searching for - let’s see what we can learn!
www.labs.greynoise.io
September 30, 2024 at 4:13 PM
September 13, 2026 at 10:26 PM
September 13, 2026 at 10:12 PM
GitLab CVE-2026-85706 was exploited within a day of disclosure. The critical path traversal flaw (CVSS 10.0) can let unauthenticated attackers read arbitrary files. #GitLab #CVE202685706 #PathTraversal
GitLab Vulnerability Exploited One Day After Disclosure
Threat actors began exploiting CVE-2026-85706 in GitLab just one day after public disclosure, taking advantage of a critical path traversal flaw that can let unauthenticated users read arbitrary files. WatchTowr also reported that mass exploitation is likely soon, while GitLab’s latest patches additionally fix CVE-2026-87719 and several other serious vulnerabilities. #GitLab...
www.hendryadrian.com
September 11, 2026 at 8:15 PM
📢 GitLab corrige une faille critique de path traversal (CVE-2026-85706) dans l'API commits

L'article couvre la divulgation et le correctif de deux vulnérabilités critiques affectant la plateforme GitLab. 🔴 Vulnérabilité…

🟢 vérification factuelle haute
#GitLab #PathTraversal #Cyberveille
GitLab corrige une faille critique de path traversal (CVE-2026-85706) dans l'API commits
L'article couvre la divulgation et le correctif de deux vulnérabilités critiques affectant la plateforme GitLab. 🔴 Vulnérabilité principale — CVE-2026-85706 (sévérité maximale) Une faille de path traversal a été identifiée dans l'API repository commits de GitLab. Elle résulte d'un confinement de chemin inapproprié et d'une absence d'enforcement d'authentification.
cyberveille.ch
September 11, 2026 at 7:30 PM
Progress ShareFile zero-day: one admin can read, write and map the whole box - storage zones forced offline. https://intel.threadlinqs.com/threat/TL-2026-1317 #ThreatIntel #ASPX #ShareFile #PathTraversal
July 14, 2026 at 4:23 PM
~Akamai~
Unauthenticated path traversal in ColdFusion RDS FILEIO handler enables arbitrary file read/write and RCE; patch via APSB26-68.
-
IOCs: CVE-2026-48282
-
#CVE202648282 #ColdFusion #PathTraversal #ThreatIntel
CVE-2026-48282: Critical Path Traversal in Adobe ColdFusion
www.akamai.com
July 9, 2026 at 4:08 AM