Windmill File-Read Flaw Under Active Exploitation
Windmill CVE-2026-29059 is being exploited to read server files without authentication; if a superadmin secret is exposed it can become a master key. Update to 1.603.3+ and review exposed instances and logs.