July 23, 2026
- Windmill CVE-2026-29059 under active exploitation. VulnCheck reports in-the-wild exploitation of an unauthenticated path traversal (CVSS 7.5) in the developer platform's
get_log_fileendpoint, allowing arbitrary server file reads (The Hacker News). · Vulnerabilities & Exploits