Articles tagged Roundup
-
Vulnerability2 CVEs: Kan & Arcane (CVE-2026-32255)
Kan (CVE-2026-32255, CVSS 8.6) and Arcane (CVE-2026-40242, 7.2) each expose an unauthenticated URL-fetching endpoint. Both VulnCheck KEV-listed Sept. 17, 2026.
-
Vulnerability9 CVEs: CodeWhale & deepseek-tui (CVE-2026-75913)
Nine CodeWhale AI coding-agent CVEs: arbitrary file write, an SSRF bypass, two auto-approved RCE paths, and five more approval-gate and sandbox failures.
-
Vulnerability5 CVEs Across 3 Vendors (CVE-2026-59971)
Five 2026 MCP-server CVEs: unauthenticated SQL execution (CVSS 10) in MySQL MCP Server, a code-execution flaw in functype-mcp-server, and three CKAN issues.
-
Vulnerability6 n8n CVEs (CVE-2026-86073)
Six n8n access-control CVEs: an OAuth consent-scope bypass, an approval-gate bypass, and four cross-user data-disclosure flaws.
-
Vulnerability3 n8n CVEs (CVE-2025-68613)
A KEV-listed, CVSS 9.9 remote code execution flaw in n8n workflow expressions, plus two related sandbox-escape CVEs in the same legacy engine.
-
Vulnerability10 n8n CVEs (CVE-2026-86075)
Ten further n8n CVEs: unauthenticated storage exhaustion, credential-exfiltration paths, a webhook signature bypass, and a KEV-listed flaw.
-
Vulnerability10 CVEs: vLLM & vLLM Hardware Plugin for Intel Gaudi (CVE-2026-73560)
Ten 2026 vLLM CVEs assessed against NVD, GitHub Advisory, and CVE.org data: an SSRF and file-read flaw, a cross-user data leak, and an OpenAI API auth bypass.
-
Vulnerability6 CVEs Across 6 Vendors (CVE-2026-86217)
A roundup of six low-severity, unrelated vulnerabilities disclosed in September 2026: information disclosure and XSS in several small PHP student/hobby projects, an out-of-bounds read in Valkey requiring cluster-mode plus attacker file access, and a disputed SSRF report in OpenAgents.