>samit_hota

Security Advisories

Disclosure bulletins

Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.

49 advisories published

SH-2026-167HighOpen

SonicWall Fixes OS Command Injection Flaw CVE-2026-83549 in SMA1000 Series

SonicWall has released patches for CVE-2026-83549, an OS command injection flaw affecting SMA1000 Series appliances that allows remote root execution.

Sep 2, 2026CVSS 7.8
SH-2026-166CriticalOpen

SonicWall Patches Critical Maximum-Severity SSRF Flaw in SMA1000 Series

A critical CVSS 10.0 SSRF vulnerability (CVE-2026-83548) in SonicWall SMA1000 appliances allows unauthenticated remote attackers to bypass security boundaries.

Sep 2, 2026CVSS 10.0
SH-2026-165CriticalOpen

Sangoma Switchvox SQL Injection (CVE-2026-9586): Critical Unauthenticated RCE Risk

A critical SQL injection vulnerability in Sangoma Switchvox (CVE-2026-9586) allows unauthenticated attackers to execute remote code on vulnerable PBX systems.

Sep 2, 2026CVSS 9.8
SH-2026-164CriticalOpen

Critical JFrog Artifactory Vulnerability Grants Unauthenticated Admin Access

A critical improper authentication vulnerability in JFrog Artifactory allows unauthenticated remote attackers to gain administrative privileges.

Sep 2, 2026CVSS 9.8
SH-2026-163CriticalOpen

Unauthenticated RCE in Kestra OSS: Analyzing CVE-2026-49869

A critical CVSS 10.0 command injection vulnerability in Kestra OSS allows unauthenticated remote attackers to execute arbitrary workflows.

Sep 2, 2026CVSS 10.0
SH-2026-162MediumOpen

CVE-2026-48710: Starlette "BadHost" Request Smuggling Vulnerability

Technical analysis of CVE-2026-48710, an HTTP request smuggling flaw in Kludex Starlette enabling authentication bypass via Host header manipulation.

Sep 2, 2026CVSS 6.5
SH-2026-161HighOpen

BerriAI LiteLLM Authentication Bypass (CVE-2026-59822) Enables Unauthenticated Access

A flaw in BerriAI LiteLLM (CVE-2026-59822) allows remote attackers to bypass authentication on MCP Streamable HTTP endpoints using arbitrary Bearer tokens.

Sep 2, 2026CVSS 8.2
SH-2026-160CriticalOpen

PaperCut NG/MF Critical Vulnerability CVE-2026-81578 Exposes Systems to Takeover

A critical missing authentication vulnerability in PaperCut NG/MF (CVE-2026-81578) allows remote attackers to alter system settings and chain exploits.

Sep 1, 2026CVSS 9.8
SH-2026-159CriticalOpen

PaperCut NG/MF Unsafe Reflection Vulnerability (CVE-2026-82078) Analysis

An analysis of CVE-2026-82078, a critical unsafe reflection vulnerability in PaperCut NG/MF allowing remote code execution via vulnerability chaining.

Sep 1, 2026CVSS 9.1
SH-2026-158CriticalOpen

Critical macOS Screen Sharing Bypass: CVE-2026-65400 Technical Advisory

Apple has patched CVE-2026-65400, a critical authentication bypass in macOS Screen Sharing allowing unauthenticated remote access.

Aug 18, 2026CVSS 9.8