CVE-2026-37072

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.

Published 2026-08-27. Last modified 2026-09-02.