Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

101 articles
285 topics
RSS Feed
CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete
cveapache artemisactivemq artemis

CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete

How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.

HOL GuardSep 10, 2026
cvepan os

BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series

How to fix CVE-2026-0310: upgrade PAN-OS to the fixed hotfix for your train (for example 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, 10.2.18-h10). Unauth XML to management web or dataplane can root PA-Series firewalls.

HOL Guard
Sep 10, 2026
cveadobe commerce

CVE-2026-77774: Magento still needs APSB26-138 after the StyleSmuggler hotfix

How to fix CVE-2026-77774: apply Adobe APSB26-138 September Isolated patches (or *-2026-sep builds) after the StyleSmuggler hotfix, then verify with php vendor/bin/patch-status

HOL Guard
Sep 8, 2026
cvefastify cli

CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE

How to fix CVE-2026-75021: upgrade fastify-cli to 8.0.1

HOL Guard
Sep 8, 2026
cveadobe commerce

BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 from repo.magento.com, then rotate the Commerce encryption key and every credential it protected

HOL
Sep 7, 2026
cveadobe commerce

BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 for Adobe Commerce / Magento Open Source, then rotate the encryption key and all protected credentials

HOL
Sep 7, 2026
hol guardguard 3

HOL Guard 3.0: Rust authority, extension-first controls, honest harness contracts

HOL Guard 3.0 puts PreToolUse on a version-matched Rust path with no Python semantic fallback, makes Local Extensions the capability vocabulary for managed-restrictive Control Sets, and keeps sync paused from meaning unprotected. Pin tip 3.0.113; do not pin yanked 3.0.0.

HOL Guard
Sep 7, 2026
cvefreeipa

BREAKING: CVE-2026-76578 lets an unauthenticated LDAP client become a FreeIPA admin

How to fix CVE-2026-76578: firewall FreeIPA LDAP ports 389/636 and disable anonymous binds until the IPA/IdM package with the hardened OTP ACI ships

HOL Guard
Sep 7, 2026
cveopenmaic

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF

How to fix CVE-2026-86259: upgrade OpenMAIC to 1.0.1

HOL Guard
Sep 6, 2026
cvemikrotik

BREAKING: CVE-2026-67276 and MikroTrick can take over MikroTik RouterOS with SSH exposed

How to fix CVE-2026-67276: upgrade RouterOS to 7.24.2, 7.23.4, or 6.49.21

HOL Guard
Sep 5, 2026
cvelibpcap

BREAKING: CVE-2026-0799 lets crafted BPF filters walk libpcap process memory

How to fix CVE-2026-0799: upgrade libpcap to 1.10.7 (covers six sibling CVEs)

HOL Guard
Sep 5, 2026
cveawslabs

CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()

How to fix CVE-2026-85787: upgrade awslabs.postgres-mcp-server to 1.1.7 or newer

HOL Guard
Sep 4, 2026
cvenango

BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code

How to fix CVE-2026-9317: upgrade nango to 0.71.6 and set NANGO_INTERNAL_AUTH_REQUIRED=true

HOL Guard
Sep 4, 2026
1 / 9

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub