Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

87 articles
242 topics
RSS Feed
BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth
cvefastifyauth bypass

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth

How to fix CVE-2026-76169: upgrade fastify to 5.12.2

HOL GuardSep 4, 2026
cvefastify

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth

How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

HOL Guard
Sep 4, 2026
cvechrome

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild

How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

HOL Guard
Sep 3, 2026
cvehermes agent

CVE-2026-71963: Hermes Agent runs Git config before the first prompt

How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

HOL Guard
Sep 3, 2026
cverancher

CVE-2026-75033: one Rancher annotation copies another cluster's secrets

How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

HOL Guard
Sep 3, 2026
cveollama

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: no patched Ollama release is available yet

HOL Guard
Sep 3, 2026
cveartifactory

BREAKING: JFrog Artifactory unauth admin on default config

How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

HOL Guard
Aug 28, 2026
cvepapercut

BREAKING: PaperCut NG/MF unauth admin config plus class-loading

How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

HOL Guard
Aug 28, 2026
cvewatchguard

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

HOL Guard
Aug 28, 2026
cveredis

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)

How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

HOL Guard
Aug 27, 2026
cveteamviewer

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)

How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

HOL Guard
Aug 26, 2026
cvechainlit

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

HOL Guard
Aug 25, 2026
cvenextjs

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)

How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

HOL Guard
Aug 25, 2026
1 / 8