
New vulnerability disclosure from @Chocapikk_ : CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K+ based on the team's ASM queries. Good stuff as always 🎉 https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce
Post summary
The message announces the discovery of CVE‑2026‑14863, an OS command injection that escalates to remote code execution in FileRun. It provides basic technical details but no PoC, exploit code, or patch information.

