>samit_hota

Security Advisories

Disclosure bulletins

Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.

49 advisories published

SH-2026-157CriticalOpen

Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)

Analysis of CVE-2026-55040, a critical Microsoft SharePoint weak authentication vulnerability allowing unauthenticated remote security bypass.

Aug 18, 2026CVSS 9.1
SH-2026-156CriticalOpen

Broadcom VMware vCenter Path Traversal Vulnerability (CVE-2026-59310): Action Required

Unauthenticated RCE in Broadcom VMware vCenter (CVE-2026-59310) enables full appliance compromise. Review attack paths and forensic triage steps.

Aug 18, 2026CVSS 9.8
SH-2026-155CriticalOpen

Critical Microsoft IKE Service RCE (CVE-2026-33824): Urgent Patch Required

A critical double-free flaw in Microsoft Internet Key Exchange (IKE) Service Extensions (CVE-2026-33824) allows unauthenticated remote code execution.

Aug 18, 2026CVSS 9.8
SH-2026-154MediumOpen

CVE-2025-62593: Cross-Site Code Injection Risk in Ray AI Framework

CVE-2025-62593 allows attackers to execute arbitrary code in Ray-Project Ray via browser-based CSRF attacks in Firefox and Safari.

Aug 17, 2026
SH-2026-153CriticalOpen

Metabase SQL Injection Vulnerability (CVE-2026-72898) Enables Full System Takeover

An unauthenticated Metabase SQL injection vulnerability (CVE-2026-72898) allows remote attackers to compromise application databases and steal credentials.

Aug 11, 2026CVSS 10.0
SH-2026-152HighOpen

CVE-2026-68820: Windows Ancillary Function Driver UAF Escalation Analysis

An analysis of CVE-2026-68820, a high-severity use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys).

Aug 11, 2026CVSS 7.0
SH-2026-151HighOpen

Cisco ASA and FTD Vulnerability CVE-2026-20349 Allows Remote Denial of Service

Cisco issued updates for CVE-2026-20349, a high-severity heap inspection flaw in ASA and FTD firewalls that allows remote unauthenticated device crashes.

Aug 11, 2026CVSS 8.6
SH-2026-150CriticalOpen

Progress LoadMaster Critical Command Injection Advisory (CVE-2026-8037)

A critical command injection vulnerability in Progress LoadMaster (CVE-2026-8037) allows unauthenticated remote attackers to execute arbitrary commands.

Aug 7, 2026CVSS 9.6
SH-2026-149CriticalOpen

CVE-2026-63077: Critical RCE Flaw in JetBrains TeamCity Agent Polling Protocol

JetBrains TeamCity contains a critical unauthenticated deserialization flaw (CVE-2026-63077) allowing remote code execution via the agent polling protocol.

Aug 5, 2026CVSS 9.8
SH-2026-148CriticalOpen

IBM Langflow CVE-2026-9198: Critical RCE Vulnerability in AI Frameworks

An unauthenticated code injection vulnerability in IBM Langflow (CVE-2026-9198) allows full remote code execution on default deployments.

Aug 4, 2026CVSS 9.8