CVE-2026-88738
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
Published 2026-09-21. Last modified 2026-09-22.