
[ZDI-26-385|CVE-2026-9772] Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability (CVSS 8.8; Credit: Swagat Kumar Mishra(https://www.linkedin.com/in/swagatkumar/)) https://www.zerodayinitiative.com/advisories/ZDI-26-385/
Post summary
The advisory warns of a remote code execution flaw in Unraid’s file upload handling (CVE‑2026‑9772), providing vulnerability details and a link to the Zero Day Initiative report.


