SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16286

CRITICAL · CVSS 9.8 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows for unrestricted file uploads of dangerous types, enabling attackers to upload a web shell to the web server running TRtek's Software Repository Management prior to version 2fb4acee. This critical flaw poses a severe risk as it can lead to unauthorized remote code execution and full control over the affected server. Organizations using this software should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-16286
Severity
CRITICAL
CVSS
9.8
EPSS
0.32%

Original NVD Description

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.