AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T12:17:17.043Z and has not been modified since then. CVE-2026-18372 is a CSS injection vulnerability in M-Files Web before 26.8.16330.2. An authenticated vault administrator can inject arbitrary CSS, affecting the web user interface displayed to other vault users. The vulnerability has a CVSS scor [truncated]
An HTML injection vulnerability exists in M-Files Web before version 26.8.16330.2. This allows an authenticated attacker to affect the web user interface contents displayed to other users. The vulnerability can lead to unauthorized modifications of the user interface, potentially disrupting normal operations or leaking sensitive information. Administrators should be aware of the potential risks and take n [truncated]
CVE-2026-0931 is a denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3. An authenticated admin user can cause the M-Files Server process to crash and fail to restart. The CVSS score is 6.9 (MEDIUM). Affected M-Files Server administrators and users with admin privileges should verify their server versions and apply updates if necessary. Official records are limited; further verif [truncated]
CVE-2026-0983 is an authenticated denial-of-service issue in M-Files Server. According to the vendor advisory referenced by NVD, a user with authentication can cause the MFserver process to crash, affecting versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3.