PatchSiren

Responsive FileManager CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Responsive FileManager CVE published 2026-05-28

CVE-2026-37266

A remote code execution vulnerability exists in Responsive FileManager version 9.14.0, specifically within the force_download.php component. The vulnerability allows a remote attacker to execute arbitrary code on affected systems. The CVSS 3.1 vector indicates network attack vector, low attack complexity, low privileges required, user interaction required, with high impact across confidentiality, integrit [truncated]