Skip to content
Path Traversal and Authorization Flaws Exploited in Recent Vulnerabilities

Path Traversal and Authorization Flaws Exploited in Recent Vulnerabilities

First seen 27 Sep 2026, 03:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •CVE-2026-93643 involves path traversal and incorrect authorization.
  • •CVE-2026-35359 has been confirmed as exploited in the wild.
  • •Public proof of concepts are available for both vulnerabilities.

Two critical vulnerabilities have been reported in 2026, CVE-2026-93643 and CVE-2026-35359. CVE-2026-93643 involves improper limitation of a pathname to a restricted directory and incorrect authorization, while CVE-2026-35359 has been confirmed as exploited in the wild. Both vulnerabilities have public proof of concepts available. CVE-2026-93643 was published on September 27, 2026, and CVE-2026-35359 was published on September 23, 2026. The affected systems include various applications that utilize these flawed authorization mechanisms. The vulnerabilities have been reported as successfully patched by users. Security professionals are advised to monitor their systems for potential exploitation and apply necessary patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
CVE-2026-35359 published
Public proof of concept available; confirmed exploitation reported by users.
db.gcve.eu
2026-09-27
CVE-2026-93643 published
Vulnerability involves path traversal and incorrect authorization; PoC available.
db.gcve.eu
Recent
Vulnerabilities successfully patched
Users reported successful patching of both vulnerabilities after their disclosure.
db.gcve.eu

More articles in this cluster (2)