ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns
CISA added CVE-2021-3199 (ONLYOFFICE Docs) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
CISA lists this as exploited in the wild. Unpatched Docs systems are exposed to active attacks now.
Treat this as an emergency.
