Announcements

Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability

  • 4th September 2026
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.Source: CISA Known Exploited Vulnerabilities Catalog — ...
Continue reading

JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

  • 4th September 2026

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-82329

Continue reading

Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • 4th September 2026

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

Continue reading

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

  • 4th September 2026

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Continue reading