MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 20 h ago, last 20 h ago, peak #5

Critical CVE-2026-70356 flagged in TMS file upload endpoint

Original: 🚨 CVE-2026-70356 — CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a

A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.

Why now: A newly disclosed critical vulnerability with remote code execution potential is being circulated among security professionals.

CVE-2026-70356TMS

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/420579