AllCyberNews

CVE-2026-70356

Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type

CVSS 9.4 critical · Toptech Systems TMS7 · published 2026-09-29

The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.

Coverage 1 source

  1. 2026-09-29 CISA Cybersecurity Advisories high Toptech TMS7 and TopHAT

    Multiple vulnerabilities affect Toptech TMS7 and TopHAT versions 7.6.3.

Mentioned with

CVE-2026-63713 CVE-2026-68068 CVE-2026-68954 CVE-2026-69662 CVE-2026-71189 CVE-2026-71302 CVE-2026-71379 CVE-2026-72507 CVE-2026-72510

Also covered