A path traversal vulnerability, identified as CVE-2026-86538, has reportedly been exploited in the wild. The flaw was publicly disclosed on September 7, 2026, and reports of its exploitation emerged just ten days later, on September 17, 2026.
The vulnerability's exploit status is currently confirmed by a single commercial research catalog, VulnCheck KEV, which listed it as exploited on September 17. The Computer Incident Response Center Luxembourg (CIRCL) aggregator also mirrors this listing. However, neither the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog nor the European Union Agency for Cybersecurity (ENISA) KEV catalog have corroborated the exploitation claim as of the latest reports.
Details regarding the specific software or product affected by CVE-2026-86538, as well as the nature of the path traversal vulnerability, were not immediately available in the public records. The Common Vulnerabilities and Exposures (CVE) record for CVE-2026-86538 was reserved and published on the same day, September 7, 2026.
The CVSS severity score for this vulnerability has not yet been assigned. Its Exploit Prediction Scoring System (EPSS) percentile stands at 61.0%, with an EPSS score of 0.98%, indicating a relatively moderate likelihood of exploitation compared to all other vulnerabilities.
Public evidence of exploitation was reported on September 17, 2026, with a single public report collected from VulnCheck and CIRCL. These sources link to an original report from previdian.com, though the authenticity of this report has not been independently verified.






