Blog
Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild
How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

CVE-2026-71963: Hermes Agent runs Git config before the first prompt
How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

CVE-2026-75033: one Rancher annotation copies another cluster's secrets
How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts
How to fix CVE-2026-85180: no patched Ollama release is available yet

BREAKING: JFrog Artifactory unauth admin on default config
How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

BREAKING: PaperCut NG/MF unauth admin config plus class-loading
How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH
How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)
How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)
How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)
How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
How to fix CVE-2026-80104: upgrade dbgpt-app to 0.8.1, then confirm the python upload user_id fix is in your build

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer
How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.