CrowdSecLive Exploit Tracker
Active ExploitationCVE-2026-65694Public Exploit

Microweber - Path Traversal (CVE-2026-65694)

PublishedJul 23, 2026
First SeenAug 19, 2026
Last Seen
Reported
CVSS8.7
cmsphpweb_application

Description

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.

psychologyCrowdSec Analysis

CVE-2026-65694 is a high-severity path traversal vulnerability in Microweber CMS through version 2.0.20. Unauthenticated remote attackers can exploit the static file controller with directory traversal sequences to read arbitrary files, potentially exposing environment configuration files, credentials, and sensitive system data through a single HTTP request.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

Based on data from the CrowdSec network, nearly all observed exploitation of CVE-2026-65694 is fully opportunistic, with attackers indiscriminately scanning the entire internet. These attacks are automated and lack any form of target selection or reconnaissance. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2026-65694 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2026-65694 is currently experiencing high visibility and active exploitation across the internet.

Attackers target the /userfiles/x endpoint with a path parameter containing directory-traversal sequences such as ../../../../../../../../etc/passwd to read arbitrary local files without authentication.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-07-23
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.