Security Advisories
Disclosure bulletins
Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.
49 advisories published
Apache Tomcat EncryptInterceptor Bypass Security Advisory (CVE-2026-34486)
Apache Tomcat CVE-2026-34486 allows attackers to bypass EncryptInterceptor in clustered environments, exposing session data and cluster communications.
CVE-2026-18556: N-able N-central Authentication Bypass Vulnerability
An authentication bypass vulnerability in N-able N-central (CVE-2026-18556) allows attackers to bypass login checks via alternate request paths.
CVE-2026-18577: Incomplete Patch Exposes N-able N-central to Auth Bypass
An incomplete fix for CVE-2026-18556 leaves N-able N-central vulnerable to authentication bypass (CVE-2026-18577). Immediate patching is required.
Cisco FMC Hard-Coded Password Flaw (CVE-2026-20316): Attack Paths & Triage
A hard-coded password vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20316) allows unauthenticated low-privileged access.
Analyzing CVE-2026-16812: Critical OS Command Injection in VeloCloud Orchestrator
CVE-2026-16812 is a maximum-severity OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem enabling remote host compromise.
FortiOS Patch Bypass (CVE-2025-68686) Exposes Persistence Vectors
CVE-2025-68686 allows remote attackers to bypass FortiOS patches for symbolic link persistence, requiring immediate remediation and forensic triage.
Analyzing CVE-2026-50522: Critical Deserialization Risk in Microsoft SharePoint
Technical analysis of CVE-2026-50522, a critical 9.8 CVSS Microsoft SharePoint deserialization vulnerability, and how to defend your enterprise.
Check Point SmartConsole Flaw Exposes Admin Tokens to Remote Attackers
A critical improper authentication vulnerability in Check Point SmartConsole (CVE-2026-16232) allows unauthenticated remote administrative access.
Securing DD-WRT Devices Against Critical UPnP Buffer Overflow Vulnerability
A detailed analysis of CVE-2021-27137, a critical stack-based buffer overflow in DD-WRT's UPnP service, including risks and remediation steps.
CVE-2026-0770: Critical RCE Vulnerability in Langflow AI Framework
A detailed security advisory on CVE-2026-0770, a critical remote code execution vulnerability in Langflow's untrusted control sphere handling.
No advisories match your search.