CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2026-02-17. EPSS: 1.8% chance of exploitation in the next 30 days.

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.

Affected products

  • TeamT5 ThreatSonar Anti-Ransomware: before 3.5.0 (fixed in 3.5.0)

Published 2024-08-12. Last modified 2026-06-17.