FR
live
tag

#path-traversal

ShinyHunters breaches Clop’s leak site through a Grav CMS path traversal flaw

On September 25, 2026, BleepingComputer confirmed that the ShinyHunters gang compromised the Clop ransomware leak site by exploiting CVE-2026-42608, an unauthenticated path traversal in Grav fixed in April but never backported to the 1.7 branch. If you still run Grav 1.7, upgrade to 1.7.53.4 without delay.

GitLab patches a CVSS 10 arbitrary file-read flaw, exploited within 24 hours

On September 11, 2026, GitLab shipped an out-of-band release for CVE-2026-85706, a CVSS 10 path traversal that reads server files with no authentication via the commits API. The flaw is already being probed in the wild — patch self-managed instances before an attacker reads secrets.yml.

Gitea CVE-2026-59774 — Unauthenticated CVSS 9.8 File Read Escalates to RCE on Every Self-Hosted Instance

On August 2, 2026, Gitea shipped a critical fix for CVE-2026-59774, a path traversal that lets an unauthenticated attacker read any server file via Org-mode markup rendering on a public repository. Worse: by reading the INTERNAL_TOKEN from app.ini, the attacker can escalate to remote code execution. Every self-hosted Gitea administrator must patch and rotate secrets immediately.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss