Redpacketsecurity
Critical Vulnerabilities Found in light0011 CMS and 92181 Markdown Parser
Article Content
Two critical vulnerabilities have been disclosed: CVE-2026-86305 in light0011 CMS and CVE-2026-86303 in 92181 Markdown parser. CVE-2026-86305 allows for unrestricted file uploads via a remote attack on the Upload::upload function, posing risks of malware delivery and data theft. CVE-2026-86303 involves an out-of-bounds read that can expose sensitive data or crash services. Both vulnerabilities were published on 2026-09-07 and affect systems using these products without available patches. The vulnerabilities are particularly dangerous for internet-facing installations and shared hosting environments. Immediate action is recommended, including disabling uploads and applying vendor fixes as they become available.
Key Points: • CVE-2026-86305 allows unrestricted file uploads in light0011 CMS. • CVE-2026-86303 poses an out-of-bounds read risk in 92181 Markdown parser. • Both vulnerabilities are actively exploitable and require urgent remediation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.