LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-67243

Published
CVSS7.2
Severityhigh
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-67243

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-67243.