Redpacketsecurity High-Risk Path Traversal Vulnerabilities in GIS and IBM Systems
Article Content
- •CVE-2026-9166 affects GIS Informatics' GisLab, allowing unauthenticated file access.
- •CVE-2026-16335 in IBM DataStage enables authenticated attackers to manipulate files.
- •Both vulnerabilities are rated high risk and require immediate remediation.
Two high-risk path traversal vulnerabilities have been reported affecting GIS Informatics' GisLab Laboratory Management System (CVE-2026-9166) and IBM DataStage on Cloud Pak for Data (CVE-2026-16335). The GIS vulnerability allows unauthenticated remote attackers to read sensitive files, impacting versions 1.4.03 to before 1.5.0. The IBM vulnerability permits authenticated attackers to read, write, or delete files, affecting version 5.4.0.0. Both vulnerabilities have a high risk rating and require urgent remediation, especially for internet-facing deployments. There is currently no indication of active exploitation for either CVE, but organizations are advised to prioritize patching and restrict access. The vulnerabilities could lead to significant data breaches or disruptions in laboratory and data processing workflows. Monitoring for unusual access patterns and reviewing logs is recommended for both systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-16335 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…