CRITICAL 9.1 CVE-2026-86930 Published 23 Sept 2026

FileMaker Server WebDirect Out-of-Bounds Read Memory Disclosure Bug

Worried this affects your website?

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker to disclose process memory.

The flaw could be triggered by uploading a specially crafted image file to a container field during thumbnail generation in FileMaker WebDirect.

This vulnerability is addressed in FileMaker Server version 26.0.3.

Reference: CVE-2026-86930 on NVD

← Back to Security News