A path traversal vulnerability in Caucho Technology's Resin web server, identified as CVE-2017-20284, was reportedly exploited on the same day it was publicly disclosed. The vulnerability was published and subsequently listed as exploited on September 18, 2026.
The flaw is specifically a path traversal issue, which could allow an attacker to access restricted directories and files outside of the intended web root. While the Common Vulnerabilities and Exposures (CVE) record for CVE-2017-20284 indicates no severity score, its inclusion in an exploited vulnerabilities catalog suggests active targeting.
The vulnerability's exploitation was first noted in the VulnCheck KEV (Known Exploited Vulnerabilities) catalog on September 18, 2026. This listing was mirrored by the CIRCL aggregator. However, the vulnerability is not present in the CISA KEV (U.S. federal) or EUVD (European Union) catalogs, which track actively exploited vulnerabilities.
Public exploitation evidence was reported on September 18, 2026, with two public reports collected from VulnCheck and CIRCL. These reports link to original sources, though their verification status by the tracking entities is not confirmed.
The timeline of CVE-2017-20284 shows a rapid progression from reservation to exploitation. The CVE was reserved on September 18, 2026, published on the same day, and first listed as exploited on September 18, 2026. The last sighting of its exploitation also occurred on this date, indicating a concentrated period of activity.






