
🟠 HIGH PRIORITY ├ CVE-2026-97359 — HFS2 2.4.0 · RCE via multipart upload template injection ├ CVE-2026-97360 — HFS2 2.4.0 · Unauth arbitrary file read/write ├ CVE-2026-61732 — Decepticon · Role-boundary forgery via ChatML tokens
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 HIGH PRIORITY ├ CVE-2026-97359 — HFS2 2.4.0 · RCE via multipart upload template injection ├ CVE-2026-97360 — HFS2 2.4.0 · Unauth arbitrary file read/write ├ CVE-2026-61732 — Decepticon · Role-boundary forgery via ChatML tokens

[CVE] CVE-2026-97360 [HIGH PRIORITY] #HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 🔗 https://exploitgrid.net/cve/CVE-2026-97360

🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-61732 CVE-2026-97359 CVE-2026-97360 CVE-2026-19072 CVE-2026-93425 ..🧵👇