LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 17, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-7694 to its Known Exploited Vulnerabilities catalog on Feb 17, 2026, with a federal patch deadline of Mar 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files…

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. Remote attackers who already hold administrator privileges on the product platform can upload malicious files that execute arbitrary system commands on the server. The flaw affects a security product intended to counter ransomware, so any successful abuse undermines the platform itself.

How it works

The weakness is categorized as CWE-434. The application does not properly validate the content of uploaded files.

Am I affected? How to find it in your systems

ThreatSonar Anti-Ransomware is typically deployed on servers or endpoints that require ransomware protection. Begin by locating every installation of the product in your environment.

How to remediate

Apply mitigations per the vendor instructions as the first action. This addresses the missing file-content validation at the source.

If you can't patch immediately

Follow the CISA directive to apply mitigations per vendor instructions, adhere to applicable BOD 22-01 guidance for any cloud services, or discontinue use of the product if mitigations cannot be obtained.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTeamT5 · ThreatSonar Anti-Ransomware
WeaknessCWE-434
Added to CISA KEVFeb 17, 2026
Federal patch deadlineMar 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities