A critical security issue affecting the open-source automation platform Windmill is being actively exploited by attackers, raising concerns for organizations that rely on the software. The vulnerability, identified as CVE-2026-29059, stems from improper validation of file paths in the application's log retrieval endpoint. By manipulating the filename parameter with directory traversal sequences, an unauthenticated attacker can access files outside the intended directory. This weakness enables unauthorized reading of sensitive files stored on the server. One of the most significant risks involves the potential exposure of the SUPERADMIN_SECRET environment variable. If this secret is configured, attackers can retrieve it from the server's environment information and use it to authenticate as a super administrator. This elevated access could allow them to execute arbitrary code through Windmill's job preview functionality, leading to a complete system compromise. However, installations that do not use the SUPERADMIN_SECRET setting are generally limited to unauthorized file disclosure rather than remote code execution. Windmill addressed the flaw by introducing filename validation and sanitization in version 1.603.3. Security researchers have observed real-world attacks targeting vulnerable Windmill deployments, with attempts focused on extracting sensitive system files. Hundreds of exposed instances across multiple countries remain at risk if they have not been updated. The attacks have also targeted environments where Windmill is deployed behind proxy services. The disclosure coincides with the addition of several other actively exploited vulnerabilities to CISA's Known Exploited Vulnerabilities catalog. These include severe flaws affecting WordPress, DD-WRT, and Langflow. The WordPress vulnerability chain, commonly referred to as WP2Shell, has attracted significant attention because it enables unauthenticated attackers to gain administrator-level access and potentially execute malicious code. Meanwhile, exploitation of the Langflow vulnerability has included credential theft, malware delivery, and attempts to access cloud metadata. Security experts strongly recommend applying the latest security patches, reviewing exposed systems for signs of compromise, and implementing continuous monitoring to reduce the risk of successful attacks.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...