Blog

Insights, updates, and deep dives on AI agents, decentralized standards, and the future of HOL.

131 articles
380 topics
RSS Feed
Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)
cvelibreofficelibreoffice calc

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

How to fix CVE-2026-63277: upgrade LibreOffice to 26.2.5 or 26.8.0. A saved Calc external data link could load a remote Java driver on open; five sibling file-read, file-write and SSRF bugs are fixed in the same release.

HOL GuardOct 5, 2026
cvenetscaler

BREAKING: NetScaler SAML memory overflow hits CISA KEV

How to fix CVE-2026-88779: upgrade NetScaler ADC/Gateway to 14.1-73.41 or 13.1-64.28 (SAML SP/IdP builds)

HOL Guard
Oct 4, 2026
cvezammad

Zammad session fixation to root hits CISA KEV

How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)

HOL Guard
Oct 2, 2026
cvefortinet

FortiMail unauthenticated path traversal hits CISA KEV

How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to upcoming 8.0.2 / 7.6.7 / 7.4.9

HOL Guard
Oct 1, 2026
cvenextjs

BREAKING: Next.js image optimizer SSRF and cache poisons in September 2026 release

How to fix CVE-2026-94483: upgrade next to 15.5.27 or 16.3.8

HOL Guard
Sep 30, 2026
cvecisco

Cisco SD-WAN Manager admin API bypass hits CISA KEV

How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

HOL Guard
Sep 30, 2026
cvecisco

BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)

How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

HOL Guard
Sep 30, 2026
cveapple

Apple CoreGraphics file OOB write hits CISA KEV

How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1

HOL Guard
Sep 29, 2026
hol guardguard extensions

Claude Code approved itself: Guard paused the self-click

Claude Code hit a warning, then ran hol-guard approvals approve on itself. HOL Guard froze it. Inbox: Allow just this once or Keep blocked.

HOL Guard
Sep 29, 2026
cveunsloth

Unsloth RCE: malicious Hugging Face model config.json injects code

How to fix CVE-2026-93348: upgrade unsloth-zoo to 2026.8.14+ and unsloth to 2026.8.20+

HOL Guard
Sep 28, 2026
cvenetscaler

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)

How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

HOL Guard
Sep 27, 2026
cvewordpress

WordPress page template include hits CISA KEV

How to fix CVE-2026-87902: upgrade WordPress to 7.1.2 (or your branch patch).

HOL Guard
Sep 25, 2026
cvesharepoint

SharePoint code injection hits CISA KEV

How to fix CVE-2026-65660: upgrade SharePoint Server to the August 2026 fixed builds (SE 16.0.19725.20522 / 2019 16.0.10417.20198 / 2016 16.0.5565.1001)

HOL Guard
Sep 25, 2026
1 / 11

HOL Guard research desk

Security research for the AI agent era

Threat guides and evidence dossiers on prompt injection, MCP tool poisoning, slopsquatting, and the attacks shaping how teams ship code with agents.

Explore the security hub