Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

84 articles
235 topics
RSS Feed
CVE-2026-71963: Hermes Agent runs Git config before the first prompt
cvehermes agentai agents

CVE-2026-71963: Hermes Agent runs Git config before the first prompt

How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

HOL GuardSep 3, 2026
cverancher

CVE-2026-75033: one Rancher annotation copies another cluster's secrets

How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

HOL Guard
Sep 3, 2026
cveollama

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: no patched Ollama release is available yet

HOL Guard
Sep 3, 2026
cveartifactory

BREAKING: JFrog Artifactory unauth admin on default config

How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

HOL Guard
Aug 28, 2026
cvepapercut

BREAKING: PaperCut NG/MF unauth admin config plus class-loading

How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

HOL Guard
Aug 28, 2026
cvewatchguard

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

HOL Guard
Aug 28, 2026
cveredis

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)

How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

HOL Guard
Aug 27, 2026
cveteamviewer

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)

How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

HOL Guard
Aug 26, 2026
cvechainlit

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

HOL Guard
Aug 25, 2026
cvenextjs

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)

How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

HOL Guard
Aug 25, 2026
cvedb gpt

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

How to fix CVE-2026-80104: upgrade dbgpt-app to 0.8.1, then confirm the python upload user_id fix is in your build

HOL Guard
Aug 25, 2026
cveopenssl

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer

How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.

HOL Guard
Aug 25, 2026
cveapache hive

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

HOL Guard
Aug 25, 2026
1 / 7