View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

xShop 3.0.3 Critical RCE via Unrestricted File Upload

🔓 CVEs & KEV

  • CVE-2026-49849 — CVSS 9.1 — xShop 3.0.3 Critical RCE via Unrestricted File Upload

  • CVE-2026-48050 — CVSS 8.8 — Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state a...

  • CVE-2026-48106 — CVSS 8.3 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync m...

  • CVE-2026-48105 — CVSS 8.3 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths wit...

  • CVE-2026-49360 — CVSS 7.8 — Recce server has unauthenticated SQL execution that allows local file read/wr...

  • CVE-2026-47735 — CVSS 7.1 — Arc has an authenticated arbitrary local-file read via DuckDB I/O functions t...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check