{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hfs2--2.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rejetto:hfs2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-97360"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HFS2 (\u003c= 2.4.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eHFS2 (HTTP File Server 2) version 2.4.0 and earlier contains a critical unauthenticated arbitrary file access vulnerability tracked as CVE-2026-97360. The vulnerability stems from a fundamental design flaw where the application's macro dispatcher lacks an authorization model, and the path resolver fails to properly constrain file operations to the intended shared directory. This combination allows unauthenticated remote attackers to perform arbitrary file read, write, append, and delete operations on the host filesystem.\u003c/p\u003e\n\u003cp\u003eBecause these operations are executed with the privileges of the HFS2 service account, a successful exploitation allows an attacker to manipulate application templates or configuration files, potentially leading to full compromise of the host system. Given the nature of the flaw, which allows for both reading sensitive data and overwriting system files, this vulnerability poses a severe risk to the confidentiality, integrity, and availability of the host platform. Users are advised to review the vendor's guidance for updates to address these architectural deficiencies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system file manipulation within the security context of the HFS2 service. An attacker could exfiltrate sensitive configuration files, modify application logic to achieve remote code execution, or delete critical system files, potentially leading to a complete service disruption or host takeover. This affects any deployment of HFS2 2.4.0 or earlier regardless of the underlying host operating system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all HFS2 instances. If an immediate upgrade is not possible, restrict network access to the HFS2 management interface to trusted segments only, as the vulnerability does not require authentication. Monitor webserver logs for unexpected requests involving path traversal or directory navigation sequences targeting HFS2 endpoints.\u003c/p\u003e\n","date_modified":"2026-09-24T14:46:59Z","date_published":"2026-09-24T14:46:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97360/","summary":"HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability allowing attackers to read, write, or delete files outside intended directories.","title":"Unauthenticated Arbitrary File Access in HFS2","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97360/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hfs:hfs2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-97359"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HFS2 (\u003c= 2.4.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["HFS"],"content_html":"\u003cp\u003eHFS2 version 2.4.0 and earlier contains a template injection vulnerability within its multipart upload handler. An unauthenticated attacker can exploit this flaw by crafting a filename containing a malicious template quoting sequence followed by an exec macro. This vulnerability allows the attacker to bypass authorization checks within the application's dispatcher mechanism, resulting in remote code execution (RCE) on the underlying host system. Given the nature of the flaw, successful exploitation leads to full compromise of the server. Organizations running affected versions of HFS2 are at high risk and should prioritize remediation or apply necessary access controls to restrict access to the upload functionality until a patch is applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary remote code execution on the host system, granting the attacker the permissions of the user running the HFS2 application. This vulnerability poses a severe threat to any environment hosting HFS2, potentially leading to total system takeover, data exfiltration, and further lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all HFS2 installations to a patched version beyond 2.4.0. If immediate patching is not possible, restrict access to the multipart upload endpoint at the web application firewall or reverse proxy layer until remediation is complete.\u003c/p\u003e\n","date_modified":"2026-09-24T14:46:53Z","date_published":"2026-09-24T14:46:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hfs2-template-injection/","summary":"HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution.","title":"Unauthenticated Remote Code Execution in HFS2 via Template Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-hfs2-template-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - HFS2 (\u003c= 2.4.0)","version":"https://jsonfeed.org/version/1.1"}