<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Path Traversal</title><description>Cybersecurity articles tagged #Path Traversal on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-66384: JFrog Artifactory Path Traversal Exploit</title><link>https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66384-jfrog-artifactory-path-traversal-exploit</guid><description>CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 02:58:16 GMT</pubDate><category>CVE-2026-66384</category><category>JFrog Artifactory</category><category>Path Traversal</category><category>CISA KEV</category><category>Supply Chain Attack</category></item><item><title>CVE-2026-29059: Windmill Unauthenticated Path Traversal Exploit</title><link>https://runtimerebel.com/blog/cve-2026-29059-windmill-unauthenticated-path-traversal-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-29059-windmill-unauthenticated-path-traversal-exploit</guid><description>Attackers are exploiting CVE-2026-29059 in Windmill&apos;s get_log_file endpoint to read sensitive server files without authentication. Patch immediately.</description><pubDate>Wed, 22 Jul 2026 13:59:27 GMT</pubDate><category>CVE-2026-29059</category><category>Windmill</category><category>Path Traversal</category><category>Active Exploitation</category></item><item><title>CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</guid><description>CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.</description><pubDate>Wed, 08 Jul 2026 06:30:23 GMT</pubDate><category>CVE-2026-48282</category><category>Adobe ColdFusion</category><category>Path Traversal</category><category>RCE</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089</title><link>https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</guid><description>Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.</description><pubDate>Tue, 16 Jun 2026 13:57:36 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category><category>CVE-2026-39813</category><category>CVE-2026-39808</category><category>CVE-2026-25089</category><category>Path Traversal</category><category>Active Exploitation</category></item><item><title>Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate</title><link>https://runtimerebel.com/blog/ivanti-sentry-cve-2023-35081-cisa-issues-urgent-3-day-patch-mandate</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-sentry-cve-2023-35081-cisa-issues-urgent-3-day-patch-mandate</guid><description>CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.</description><pubDate>Fri, 12 Jun 2026 09:33:30 GMT</pubDate><category>Ivanti Sentry</category><category>CVE-2023-35081</category><category>CISA KEV</category><category>Path Traversal</category><category>Rce Chain</category></item><item><title>CVE-2024-5027: Langflow Path Traversal Exploited in Attacks</title><link>https://runtimerebel.com/blog/cve-2024-5027-langflow-path-traversal-exploited-in-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-5027-langflow-path-traversal-exploited-in-attacks</guid><description>Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.</description><pubDate>Thu, 11 Jun 2026 05:41:21 GMT</pubDate><category>CVE-2024-5027</category><category>Langflow</category><category>AI Security</category><category>Path Traversal</category><category>RCE</category></item><item><title>CVE-2024-28995: SolarWinds Serv-U Path Traversal Exploited — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-28995-solarwinds-serv-u-path-traversal-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-28995-solarwinds-serv-u-path-traversal-exploited-patch-now</guid><description>SolarWinds patches CVE-2024-28995, a high-severity path traversal flaw in Serv-U exploited in the wild. Learn how to detect and mitigate this file disclosure risk.</description><pubDate>Mon, 08 Jun 2026 09:45:15 GMT</pubDate><category>SolarWinds</category><category>Serv U</category><category>CVE-2024-28995</category><category>Path Traversal</category><category>Exploited in the Wild</category></item><item><title>CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide</title><link>https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41551-siemens-ros-path-traversal-remediation-guide</guid><description>Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.</description><pubDate>Thu, 14 May 2026 20:40:37 GMT</pubDate><category>CVE-2026-41551</category><category>Siemens ROS</category><category>Path Traversal</category><category>Critical Manufacturing</category><category>ICS Security</category></item><item><title>Android Dirty Stream Path Traversal: Detecting and Patching App Exploits</title><link>https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</guid><description>Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.</description><pubDate>Mon, 20 Apr 2026 05:08:30 GMT</pubDate><category>Android</category><category>Dirty Stream</category><category>Path Traversal</category><category>Mobile Security</category><category>Microsoft Threat Intelligence</category></item><item><title>CVE-2024-32113: Apache OFBiz RCE Exploited for Mirai Botnet</title><link>https://runtimerebel.com/blog/cve-2024-32113-apache-ofbiz-rce-exploited-for-mirai-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-32113-apache-ofbiz-rce-exploited-for-mirai-botnet</guid><description>Technical analysis of CVE-2024-32113 exploitation in Apache OFBiz. Learn how attackers use path traversal to deploy Mirai botnet malware and how to patch.</description><pubDate>Mon, 06 Apr 2026 05:02:01 GMT</pubDate><category>CVE-2024-32113</category><category>Apache OFBiz</category><category>Mirai</category><category>RCE</category><category>Path Traversal</category></item><item><title>CVE-2024-50498: Wing FTP Server Exploited in RCE Chains — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-50498-wing-ftp-server-exploited-in-rce-chains-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-wing-ftp-server-exploited-in-rce-chains-patch-now</guid><description>CISA adds CVE-2024-50498 to its KEV catalog after reports of active exploitation. Learn how to secure Wing FTP Server versions prior to 7.5.0 from RCE chains.</description><pubDate>Mon, 16 Mar 2026 20:16:23 GMT</pubDate><category>CVE-2024-50498</category><category>Wing FTP</category><category>Path Traversal</category><category>CISA KEV</category><category>RCE</category></item><item><title>CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog</title><link>https://runtimerebel.com/blog/cisa-adds-two-cisco-sd-wan-exploits-to-kev-catalog</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-adds-two-cisco-sd-wan-exploits-to-kev-catalog</guid><description>CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.</description><pubDate>Wed, 25 Feb 2026 20:17:03 GMT</pubDate><category>CVE-2022-20775</category><category>CVE-2026-20127</category><category>Cisco Catalyst SD WAN</category><category>CISA KEV</category><category>Active Exploitation</category><category>Path Traversal</category><category>Authentication Bypass</category></item><item><title>Valmet DNA Engineering Web Tools Vulnerable to Path Traversal</title><link>https://runtimerebel.com/blog/valmet-dna-engineering-web-tools-vulnerable-to-path-traversal</link><guid isPermaLink="true">https://runtimerebel.com/blog/valmet-dna-engineering-web-tools-vulnerable-to-path-traversal</guid><description>Unauthenticated attackers can exploit CVE-2025-15577 in Valmet DNA Engineering Web Tools to gain arbitrary file read access across critical infrastructure.</description><pubDate>Tue, 24 Feb 2026 12:25:56 GMT</pubDate><category>CVE-2025-15577</category><category>Valmet</category><category>ICS</category><category>Path Traversal</category><category>CWE-22</category><category>Critical Manufacturing</category><category>Energy</category></item></channel></rss>