cbcvebase.
CVE-2026-0983
published 2026-05-18

CVE-2026-0983: Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the…

PriorityP434high7.1CVSS 4.0
AVNACLATNPRLUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.23%
13.2th percentile
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash

Affected

3 ranges
VendorProductVersion rangeFixed in
m-files_corporationm-files_server< 26.5.16015.026.5.16015.0
m-files_corporationm-files_server>= LTS 25.8.15085.13 < LTS 25.8.15085.24LTS 25.8.15085.24
m-files_corporationm-files_server>= LTS 26.2.15718.8 < LTS 26.2.15718.10LTS 26.2.15718.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.