# CVE-2026-65694: Microweber - Path Traversal

> Live exploitation tracking for CVE-2026-65694 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-65694

## Key facts

- **Exploitation phase:** Active Exploitation. The vulnerability is actively exploited at scale across the internet, often via automated tools and large attack campaigns.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** Microweber
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** cms, php, web_application

## Description

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.

## CrowdSec analysis

[CVE-2026-65694](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-65694) is a high-severity path traversal vulnerability in Microweber CMS through version 2.0.20. Unauthenticated remote attackers can exploit the static file controller with directory traversal sequences to read arbitrary files, potentially exposing environment configuration files, credentials, and sensitive system data through a single HTTP request.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

Based on data from the CrowdSec network, nearly all observed exploitation of CVE-2026-65694 is fully opportunistic, with attackers indiscriminately scanning the entire internet. These attacks are automated and lack any form of target selection or reconnaissance.
Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2026-65694 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2026-65694 is currently experiencing high visibility and active exploitation across the internet.

Attackers target the `/userfiles/x` endpoint with a `path` parameter containing directory-traversal sequences such as `../../../../../../../../etc/passwd` to read arbitrary local files without authentication.

## Timeline

- 2026-07-23: CVE Published. CVE-2026-65694 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2026-65694 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-65694 for the first time.

## References

- https://github.com/microweber/microweber/pull/1181
- https://www.vulncheck.com/advisories/microweber-cms-path-traversal-via-servestaticfilecontroller
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-65694.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-65694) follows observed exploitation activity for CVE-2026-65694. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
