OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97360

CRITICAL · CVSS 10 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

HFS2 versions 2.4.0 and earlier are vulnerable to an unauthenticated arbitrary file access flaw, enabling attackers to read, write, append, and delete files across the filesystem where the HFS service account has access. This critical vulnerability can severely compromise the confidentiality, integrity, and availability of the affected systems. Organizations using HFS2 should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97360
Severity
CRITICAL
CVSS
10
EPSS
0.32%

Original NVD Description

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of authorization model combined with the path resolver's failure to confine absolute paths to manipulate the template engine and compromise the confidentiality, integrity, and availability of the host.