CVE-2026-97359

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed by an exec macro, which bypasses the authorization check in the dispatcher to execute arbitrary commands on the underlying host system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-24); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-24: 2Mentions · 2026-09-25: 109-2409-25
Referenced assets3 URLs
Full discourse3 posts
  • ThreatAft@ThreatAft

    🚨 HFS2 CVE-2026-97359 — CVSS 10.0 Unauthenticated RCE. Multipart upload filename escapes template quoting context. exec macro runs without auth check. Affected: HFS2 2.0.0–2.4.0 → https://threataft.com/articles/hfs2-cve-2026-97359-unauthenticated-template-injection-rce #HFS2 #Rejetto #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    1001035
    43 followersView on X
  • SecAlerts@SecAlertsCo

    📁 Rejetto HFS2 2.4.0: unauthenticated RCE via multipart upload filename template injection. CVE-2026-97359 scores a perfect CVSS 10. No auth, no interaction, full system compromise. Upgrade now. #cybersecurity #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-97359?utm_campaign=x https://t.co/wOolFT9rD7

    00000154
    889 followersView on X
  • Severity Daily@severitydaily

    VulnCheck (@VulnCheckAI) scored two new unauthenticated Rejetto HFS 2.x flaws 10.0. The researcher who found them scored both 9.8 — the gap is one scope metric. No patch, no exploitation reported. https://severitydaily.com/rejetto-hfs2-cve-2026-97359-97360-vulncheck-10-0-researcher-9-8-no-fix/

    0000037
    24 followersView on X

Explore more