CVE-2026-66665: Brandexponents Type Hub

Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

Affected products

Published 2026-08-06. Last modified 2026-08-12.