{
  "title": "CVE of the day — CVE-2026-97360 (CVSS 10,0, critical)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-97360 (CVSS 10,0, critical)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-97360: critical vulnerability, CVSS 10,0/10, type missing authorization, exploitable"
    }
  ],
  "description": "CVE-2026-97360: critical vulnerability, CVSS 10,0/10, type missing authorization, exploitable remotely, without privileges, without user interaction. HFS2 version 2.4.0 and earlier contains an unuthenticated arbitrary file access vulnerability that allows unuthenticated attackers to read, write..",
  "keywords": [
    "c",
    "cve-2026-97360",
    "vulnerability",
    "critical vulnerability",
    "c",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 97",
      "subtitle": "CVSS 10.0",
      "text": "CVE-2026-97360: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "Missing authorization",
      "subtitle": "missing authorization · CVSS v3.1",
      "text": "HFS2 version 2.4.0 and earlier contains an unuthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-09-26T00:45:19.750Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-09-26",
  "poster": "cve-2026-09-26-en.jpg",
  "preview": "cve-2026-09-26-en.gif",
  "og_card": "cve-2026-09-26-en.og.jpg",
  "audiogram": "cve-2026-09-26-en.audiogram.mp4",
  "captions": "cve-2026-09-26-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-97360: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database. HFS2 version 2.4.0 and earlier contains an unuthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-97360: Critical gravity, CVSS score 10,0 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "HFS2 version 2.4.0 and earlier contains an unuthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}