Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

127 articles
361 topics
RSS Feed
BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release
cvenextjsssrf

BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release

How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8

HOL GuardSep 30, 2026
cvecisco

Cisco SD-WAN Manager admin API bypass hits CISA KEV

How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

HOL Guard
Sep 30, 2026
cvecisco

BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)

How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

HOL Guard
Sep 30, 2026
cveapple

Apple CoreGraphics file OOB write hits CISA KEV

How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

HOL Guard
Sep 29, 2026
hol guardguard extensions

Claude Code approved itself: Guard paused the self-click

Claude Code hit a warning, then ran hol-guard approvals approve on itself. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.

HOL Guard
Sep 29, 2026
cveunsloth

Unsloth RCE: malicious Hugging Face model config.json injects code

How to fix CVE-2026-93348: upgrade unsloth-zoo to 2026.8.14+ and unsloth to 2026.8.20+

HOL Guard
Sep 28, 2026
cvenetscaler

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)

How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

HOL Guard
Sep 27, 2026
cvewordpress

WordPress page template include hits CISA KEV

How to fix CVE-2026-87902: upgrade WordPress to 7.1.2 (or your branch patch).

HOL Guard
Sep 25, 2026
cvesharepoint

SharePoint code injection hits CISA KEV

How to fix CVE-2026-65660: upgrade SharePoint Server to the August 2026 fixed builds (SE 16.0.19725.20522 / 2019 16.0.10417.20198 / 2016 16.0.5565.1001)

HOL Guard
Sep 25, 2026
cveadobe commerce

Magento incorrect authorization hits CISA KEV

How to fix CVE-2026-71362: upgrade Adobe Commerce and Magento Open Source to the matching *-2026-aug security train (or APSB26-92 Isolated patch)

HOL Guard
Sep 24, 2026
cvef5

F5 BIG-IP APM OAuth RCE hits CISA KEV

CVE-2026-94127 affects BIG-IP APM virtual servers configured as OAuth Authorization Servers. Install the F5 engineering hotfix for your branch.

HOL Guard
Sep 22, 2026
ghsacve

BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)

How to fix CVE-2026-94545: upgrade next to 16.3.6 (15.5.26 hardening if you stay on 15.x)

HOL Guard
Sep 22, 2026
cveerlang

Your Erlang TLS 1.3 client can trust a server with no certificate

How to fix CVE-2026-89422: upgrade Erlang/OTP to 29.1.1, 28.5.0.7, or 27.3.4.18

HOL Guard
Sep 22, 2026
1 / 11

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub