Path traversal vulnerabilities
Path traversal lets an attacker read or write files outside the intended directory by smuggling ../ sequences into file paths. In appliances and web applications it often exposes configuration files and credentials — and when writes are possible, it escalates to code execution via planted files.
Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged path traversal, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.
Latest path traversal advisories
[UPDATE] [mittel] Red Hat OpenShift: Schwachstelle ermöglicht Manipulation von Dateien
[UPDATE] [mittel] GNU tar: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
[UPDATE] [hoch] Rapid7 Velociraptor: Mehrere Schwachstellen
[UPDATE] [niedrig] cpio: Mehrere Schwachstellen
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
[UPDATE] [hoch] Rsync: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux: Mehrere Schwachstellen
[UPDATE] [niedrig] Python: Schwachstelle ermöglicht Path Traversal
[UPDATE] [hoch] MongoDB: Mehrere Schwachstellen
USN-8723-1: SPICE vdagent vulnerabilities
USN-8717-1: Apache Tika vulnerability
[NEW] [high] Drupal Extensions: Multiple vulnerabilities
[NEW] [high] IBM AIX and VIOS: Multiple vulnerabilities
Progress Software security advisory (AV26-875)
[NEW] [high] Red Hat Enterprise Linux (open-iscsi): Multiple vulnerabilities
[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilities
[UPDATE] [medium] VMware Tanzu Spring Framework (MVC and WebFlux): Multiple vulnerabilities
[UPDATE] [medium] libssh: Multiple vulnerabilities enable file manipulation and DoS
[UPDATE] [high] Red Hat Ansible Automation Platform: Multiple vulnerabilities
[UPDATE] [high] Samba: Multiple vulnerabilities
USN-8704-1: GNU cpio vulnerabilities
[UPDATE] [high] Red Hat Enterprise Linux (git-lfs, opentelemetry-collector): Multiple vulnerabilities
[NEW] [high] IBM Concert: Multiple vulnerabilities
[NEW] [high] Budibase: Multiple vulnerabilities
NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems
[NEW] [medium] n8n: Vulnerability enables file manipulation and information disclosure
[NEW] [high] Wazuh: Multiple vulnerabilities
[NEW] [medium] WP Royal Royal Elementor Addons: Multiple vulnerabilities
[UPDATE] [medium] Podman: Vulnerability enables file manipulation
[UPDATE] [medium] Varnish HTTP Cache: Vulnerability enables manipulation of files, disclosure of information and circumvention of security measures
[UPDATE] [medium] Varnish HTTP Cache: Vulnerability enables manipulation of files
[UPDATE] [medium] Varnish HTTP Cache: Multiple vulnerabilities enable manipulation of files
[UPDATE] [medium] Red Hat Enterprise Linux (abrt): Multiple vulnerabilities
DSA-6475-1 suricata-update - security update
DSA-6472-1 bubblewrap - security update
DSA-6473-1 libdbi-perl - security update
CVE-2026-66384: JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
[NEW] [high] rclone: Multiple vulnerabilities
NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch
[NEW] [medium] IBM SPSS Modeler: Vulnerability allows file manipulation
[NEW] [high] Notepad++: Multiple vulnerabilities
[NEW] [high] Apache CloudStack: Multiple vulnerabilities
[NEW] [high] TP-Link Omada Gateway: Multiple vulnerabilities
CVE-2026-15415 - Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
Other vulnerability classes
New path traversal advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.