FR
live
tag

#cve-2026-42608

ShinyHunters breaches Clop’s leak site through a Grav CMS path traversal flaw

On September 25, 2026, BleepingComputer confirmed that the ShinyHunters gang compromised the Clop ransomware leak site by exploiting CVE-2026-42608, an unauthenticated path traversal in Grav fixed in April but never backported to the 1.7 branch. If you still run Grav 1.7, upgrade to 1.7.53.4 without delay.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss