Tech News
← Home  ·  All topics

Path Traversal

4 GoKawiil briefs on this topic

Attackers exploit WordPress CVE-2026-87902 within hours of patch release

Security firm Patchstack says threat actors began exploiting a critical WordPress path traversal flaw, CVE-2026-87902, to write files that execute shell commands, after initial reconnaissance traffic surged tenfold. The bug, discovered by researcher Robert Ressl and rated 9.2/10 in severity, allows unauthenticated attackers to trick get_page_template() into loading arbitrary local PHP files under certain theme and server configurations. WordPress patched the issue in version 7.1.2 and backported fixes to branches as old as 4.7.

Check Point patches actively exploited zero-day in Security Management Server

Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.

CISA confirms active exploitation of critical GitLab path traversal flaw CVE-2026-85706

CISA has added a maximum-severity GitLab vulnerability, CVE-2026-85706, to its known exploited vulnerabilities catalog after security firm watchTowr detected attackers scanning the internet for unpatched servers. The flaw allows unauthenticated attackers to read credentials and sensitive files from GitLab instances via a single crafted HTTP request to the repository commits API. GitLab patched the issue in versions 19.3.2, 19.2.6, and 19.1, but federal agencies now have just three days to remediate under a binding directive.

GitLab patches maximum-severity path traversal bug in commits API

GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.