CVE-2026-67243: Refirio FREO2
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.
Affected products
- Refirio FREO2: before 2.0.0-alpha-14 (fixed in 2.0.0-alpha-14)
Published 2026-08-04. Last modified 2026-08-28.