CVE-2026-2368: Lenovo Filez
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
Affected products
- Lenovo Filez: before 10.12.3.0 (fixed in 10.12.3.0); before 11.1.0.35 (fixed in 11.1.0.35)
Published 2026-03-11. Last modified 2026-08-19.