CVE-2026-44666
Attacker can run any command on HRConvert2 by uploading a malicious file.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in HRConvert2 allows anyone to run commands on the server by uploading a file with a malicious name. This could lead to a full system compromise. Update to version 3.3.8.