Security3 min read
Critical Windmill CVE-2026-29059 Under Active Exploitation in the Wild
Tags Infrastructure · OSS
The Hacker News·

A high-severity security flaw in the open-source developer platform Windmill (CVE-2026-29059, CVSS score: 7.5) has come under active exploitation, involving unauthenticated path traversal affecting the get_log_file endpoint that could allow remote code execution.
Technical significance
The active exploitation of this critical Windmill vulnerability highlights the urgent need for organizations using open-source developer platforms to implement immediate patches and strengthen their security posture, as attackers are actively targeting this widely used tool.