Directory Traversal is a vulnerability tracked across 7 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed October 27, 2025; most recent activity July 20, 2026.
Directory Traversal is a web vulnerability that allows attackers to access restricted files or directories by manipulating user-supplied input (for example using ../ sequences) due to insufficient input validation or improper path handling. It enables data exposure and can facilitate broader compromises in web-facing applications, making it a high-priority risk for defenders. Recent reporting highlights active exploitation of a CVE associated with traversal-type flaws, underscoring the real-world danger of this issue.
TP-Link has patched multiple critical vulnerabilities in its Archer NX router series, specifically affecting models NX200, NX210, NX500, and NX600. The most severe flaw, CVE-2025-15517, allows unauthenticated attackers…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
The Spring development team disclosed four vulnerabilities in the Spring Cloud Config Server, with severity ratings from medium to critical. These vulnerabilities allow unauthorized access to arbitrary files and the…
A significant directory traversal vulnerability has been identified in the Rocky Linux javapackages-tools, affecting various modules. This flaw arises from overly broad permissions, which could allow a compromised…
A vulnerability identified as CVE-2025-11001 in 7-Zip affects all versions prior to 25.00, allowing remote code execution. NHS Digital has issued alerts following reports of active exploitation targeting both public and…
A critical vulnerability in 7-Zip, identified as CVE-2025-11001, is being actively exploited, allowing remote code execution. The flaw affects all versions prior to 25.00 and has prompted warnings from NHS Digital and…
On February 9, 2026, Check Point reported on active ransomware threats and vulnerabilities affecting Ivanti Endpoint Manager. Specifically, CVE-2026-1281 and CVE-2026-1340 were published on January 29, 2026, with…