VulnCheck says CVE-2026-29059 in Windmill is being actively exploited to abuse the get_log_file endpoint for arbitrary file reads, with attackers trying to access sensitive data such as /etc/passwd and, in some cases, SUPERADMIN_SECRET. CISA has also added multiple flaws to its KEV catalog, while exploitation activity is surging against WordPress wp2shell and Langflow CVE-2026-0770. #Windmill #CVE-2026-29059 #wp2shell #CVE-2026-0770 #CISA
Keypoints
- CVE-2026-29059 affects Windmillβs get_log_file endpoint with unauthenticated path traversal.
- Attackers are using ../ sequences to read arbitrary files on vulnerable systems.
- SUPERADMIN_SECRET exposure could enable superadmin access and code execution.
- VulnCheck found about 170 vulnerable Windmill systems exposed across 24 countries.
- CISA added Windmill-adjacent active threats, including wp2shell, DD-WRT CVE-2021-27137, and Langflow CVE-2026-0770, to its KEV catalog.
Read More: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html