Announcements

JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

  • 2nd September 2026

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-82329

Continue reading

Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • 2nd September 2026

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

Continue reading

Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

  • 2nd September 2026
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.Source: CISA ...
Continue reading

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

  • 2nd September 2026

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Continue reading