Blog
Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

CVE-2026-72603: wg-easy WireGuard UI Lets Low-Privilege Users Execute Root Commands
wg-easy 15.3.0 has an OS command injection vulnerability in its client creation flow. Users with clients.create permission can inject WireGuard PostUp directives via newlines in the client name field, achieving root code execution.

CVE-2026-72533: Portainer CE Authentication Bypass Grants Root Access to Docker Hosts
Portainer CE through 2.44.0 has an authentication bypass in its Docker proxy endpoint. Low-privileged users can craft non-canonical URL paths to bypass authorization checks and gain root-level access to the Docker host.

CVE-2026-58231: Unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter
SAP Commerce Cloud Data Hub Adapter ships with a default authentication client. An unauthenticated attacker can submit crafted input to validation-lacking functions, achieving arbitrary code execution. No fix available yet.

CVE-2026-33921: Nozomi Arc Shipped With Insecure Npcap Driver, Exposing Traffic to Non-Admin Users
The Windows installer for Nozomi Arc before v2.7.0 deployed the Npcap packet capture driver without enabling its administrator-only access restriction. Any local user could capture traffic and send raw packets. Fixed in version 2.7.0.

CVE-2026-33922: Nozomi Arc Path Traversal Lets Admins Delete Arbitrary Files on OT Security Appliances
A path traversal vulnerability in Nozomi Arc before v2.7.0 lets local web interface administrators delete arbitrary files by submitting crafted archive names in the Offline archives feature. Fixed in version 2.7.0.

CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes
Undertow AJP CLIENT-CERT authentication bypass via forged ssl_cert and is_ssl attributes. An unauthenticated attacker who reaches port 8009 can bypass mutual TLS authentication. Part of the Ghostcat-class AJP trust model flaws.

CVE-2026-15555: JBoss EAP Deserialization RCE via Unfiltered River Unmarshaller in Session Replication
JBoss EAP and WildFly cluster deserialization RCE. The Infinispan session replication path deserializes through JBoss Marshalling River unmarshaller with no class filtering. Network access to the clustering port yields code execution on every cluster node.

CVE-2026-72693: kbd openvt Privilege Escalation Enables Passwordless Root Login
The kbd package, shipped on virtually every Linux distribution, contains a local privilege escalation in openvt -u. A flaw in how authenticate_user() verifies process ownership lets an unprivileged user trigger a passwordless login -f root on a new virtual terminal.

CVE-2026-19519: Claircore RPM Header Parser Crash Takes Down Container Vulnerability Scanners
CVE-2026-19519 is a denial-of-service vulnerability in claircore, the Go library behind Red Hat's Clair container scanner. A crafted RPM header in a container layer triggers an unchecked type assertion (CWE-617) that panics the indexer process. CVSS 4.3 MEDIUM.

CVE-2026-19418: TYPO3 CMS Backend Access Control Bypass via Referrer Enforcement Failure
TYPO3 CMS 13.0.0-13.4.33 and 14.0.0-14.3.5 ship a broken referrer check that became inert when v13 moved the backend entry point to the site root. Any same-domain JavaScript can invoke backend and Install Tool endpoints with an authenticated session. Fixed in 13.4.34 and 14.3.6.

CVE-2026-16053: ManageEngine M365 Backup Module Path Traversal
Path traversal in the Exchange Online backup module of ManageEngine M365 Manager Plus and M365 Security Plus builds prior to 4820 allows authenticated operators to write backup data to arbitrary filesystem locations. CVSS 3.1 score 8.5 HIGH, CWE-23. Fixed in build 4820.

CVE-2026-19391: Red Hat insights-core Leaks SSSD and Pacemaker Passwords Into Uploaded Archives
CVE-2026-19391 is a credential disclosure bug in Red Hat insights-core where the password redaction layer only filters values under the key "password", leaving SSSD LDAP bind passwords and Pacemaker fence device credentials in cleartext within archives uploaded to console.redhat.com.

CVE-2026-18348: Velociraptor NETWORK ACL Bypass via Upload VQL Plugins
Incorrect authorization (CWE-863, CVSS 4.1) in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins lets an analyst-role user bypass the NETWORK ACL for reconnaissance and data exfiltration. Fixed in 0.77.2.