
🚨 HFS2 CVE-2026-97359 — CVSS 10.0 Unauthenticated RCE. Multipart upload filename escapes template quoting context. exec macro runs without auth check. Affected: HFS2 2.0.0–2.4.0 → https://threataft.com/articles/hfs2-cve-2026-97359-unauthenticated-template-injection-rce #HFS2 #Rejetto #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel


