SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-19852

MEDIUM · CVSS 6.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

NewSiteServer (NSS) by CyberTutor is vulnerable to an Arbitrary File Upload flaw that allows unauthenticated remote attackers to upload malicious files, including HTML, potentially leading to cross-site scripting attacks. Organizations using NSS should prioritize addressing this vulnerability to mitigate the risk of unauthorized file uploads and subsequent exploitation. This is particularly critical for environments that handle sensitive user data or rely on web-based functionalities.

CVE
CVE-2026-19852
Severity
MEDIUM
CVSS
6.1
EPSS
0.23%

Original NVD Description

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.