CVE-2026-43752: An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This ...
Added to the CISA Known Exploited Vulnerabilities catalog on 09 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.9.
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.
Required action: Review and patch if applicable to your AI infrastructure.