Bypasses filename extension blocklist using zero-width space (U+200B) to upload .htaccess and PHP webshell, achieving remote code execution. Patch bypass for CVE-2026-27636.
Is your app exploitable through CVE-2026-28289?