Juan F Gallego[verified]@jfernandoggActive Exploitation
ShinyHunters claim to have actively exploited CVE-2026-42608 in Grav CMS 1.7.43, and Grav has released a patch (1.7.53.4) urging users to upgrade.
z3n[verified]@zench4nPatch
The advisory urges patching orchestration layers and monitoring for path traversal vulnerabilities such as CVE-2026-42608.
P.K. Sharma[verified]@_pksharmaPatch
The advisory for CVE‑2026‑42608 initially listed only a beta version as the fix, but a production backport (1.7.53.4) was later released, highlighting the need to correctly interpret fixed‑version fields. The vulnerability is an unauthenticated path traversal in Grav’s FormFlash component with CVSS 8.8, though no PoC or confirmed exploitation is reported.
Arnaud Wallon[verified]@arwallonActive Exploitation
The tweet confirms that CVE-2026-42608, a path traversal flaw in Grav CMS 1.7, was exploited to compromise the Clop ransomware group's site, notes that a patch (version 1.7.53.4) is forthcoming, and urges immediate updates.
Cybersecurity News Everyday[verified]@TweetThreatNewsActive Exploitation
ShinyHunters exploited an unauthenticated path traversal flaw in Grav CMS to deface Clop's leak site, prompting a Tor migration; Grav confirmed CVE-2026-42608 and patched via version 1.7.53.4.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The tweet reports that actor ShinyHunters actively exploited CVE-2026-42608 (path traversal) to breach Clop's infrastructure, providing technical details on the attack vector while confirming in-the-wild usage without linking PoC code or a vendor patch.
Anthony Bahn[verified]@HoustonIntrove1Active Exploitation
The post reports that CVE-2026-42608, a path traversal vulnerability in Grav, was actively exploited by ShinyHunters to deface a site, and notes that a patched version (1.7.53.4) has been released.
NEXSIGHT@NEXSIGHTNEWSActive Exploitation
The text reports that Grav CMS released emergency backport fix version 1.7.53.4 for CVE-2026-42608, an unauthenticated file-write vulnerability that has been actively exploited in the wild by the Clop ransomware group.