Tag: cve 2026 42608
1 article

ShinyHunters Exploits Grav CMS Flaw to Breach Clop Leak Site
The Grav CMS flaw, tracked as CVE-2026-42608, was exploited by ShinyHunters to breach the Clop gang's leak site, and the vulnerability has since been patched in Grav's 2.0 and 1.7 branches. Grav confirmed the legitimacy of the flaw and the threat actor's description, and has implemented a fix to prevent further attacks.