Announcements

Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability

  • 3rd September 2026
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.Source: CISA Known Exploited Vulnerabilities Catalog — ...
Continue reading

JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

  • 3rd September 2026

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-82329

Continue reading

Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • 3rd September 2026

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

Continue reading

Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

  • 3rd September 2026
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.Source: CISA ...
Continue reading