CVE-2026-75164
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenti
CVSS
6.5
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Sep 4, 2026 · Last modified: Sep 8, 2026 · CWE-552
0.4%EPSS · 30 days0.4%
2026-09-052026-09-09
An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-688315.5 MED22.5%
——7Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.2dCVE-2026-748536.8 MED14.3%
——4The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.2dCVE-2026-67402—24.9%
——7An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.23hCVE-2026-851758.8 HIG8.5%
——3SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenticated users receive RoleAdministrator in v3.8.1, any user (or any client on a default no-auth-code instance) can retrieve these private keys via POST /api/file/getFile. On deployments with TLS enabled, this allows decryption of captured HTTPS traffic (key.pem) and forging of certificates trusted by clients that imported SiYuan's CA (ca.key).2dCVE-2026-737365.3 MED16.5%
——5A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.7dCVE-2026-737355.4 MED5.5%
——2Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access some information beyond their privilege level. Successful exploitation could allow an attacker to obtain limited information and/or make limited changes beyond what is authorized by the user's existing privilege level.7d