A path traversal vulnerability in the Werkzeug web application library, identified as CVE-2024-49766, has been linked to ransomware exploitation. While the CVE was reserved on October 18, 2024, and published on October 25, 2024, evidence of its exploitation emerged approximately 705 days later, on September 30, 2026.
The vulnerability's exploitation was first noted in a commercial research catalog on September 30, 2026. This date marks the earliest known listing of CVE-2024-49766 as exploited, measured from its CVE publication date. The claim of exploitation is currently supported by a single catalog, with no corroborating listings from other major vulnerability databases such as CISA KEV or EUVD ENISA.
Public evidence of the exploitation was reported on September 30, 2026, referencing a report from Zscaler's Threatlabz. This report is cited as the source for the exploitation claim, which has been collected and mirrored by vulnerability aggregators. However, the original source of the exploitation claim has not been independently verified.
The Werkzeug library is a widely used WSGI utility library for Python, forming the foundation for many web applications. A path traversal flaw allows an attacker to access files and directories stored outside the intended web root directory by manipulating file paths in user-supplied input. Such vulnerabilities can lead to unauthorized information disclosure, or in more severe cases, remote code execution if combined with other weaknesses.
The CVSS severity score for CVE-2024-49766 is not specified in the available records, but its EPSS (Exploit Prediction Scoring System) score is 0.78%, placing it in the 54.2th percentile. This score indicates a relatively low probability of exploitation compared to all other vulnerabilities. Despite this, the confirmed use in ransomware attacks highlights the potential impact of even seemingly lower-risk vulnerabilities.
The delayed exploitation, occurring nearly two years after the CVE's initial publication, suggests that attackers may have either recently discovered how to weaponize the flaw or that its use has only now been publicly documented. This extended window between disclosure and observed exploitation underscores the ongoing threat posed by older vulnerabilities that may not receive immediate patching attention.
Organizations utilizing applications built with Werkzeug are advised to ensure their systems are updated to patched versions to mitigate the risk associated with CVE-2024-49766. The link to ransomware activity emphasizes the critical need for timely vulnerability management and patching strategies.






