>samit_hota

Security Advisories

Disclosure bulletins

Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.

49 advisories published

SH-2026-147HighOpen

Apache Tomcat EncryptInterceptor Bypass Security Advisory (CVE-2026-34486)

Apache Tomcat CVE-2026-34486 allows attackers to bypass EncryptInterceptor in clustered environments, exposing session data and cluster communications.

Aug 4, 2026CVSS 7.5
SH-2026-146HighOpen

CVE-2026-18556: N-able N-central Authentication Bypass Vulnerability

An authentication bypass vulnerability in N-able N-central (CVE-2026-18556) allows attackers to bypass login checks via alternate request paths.

Aug 4, 2026CVSS 7.4
SH-2026-145MediumOpen

CVE-2026-18577: Incomplete Patch Exposes N-able N-central to Auth Bypass

An incomplete fix for CVE-2026-18556 leaves N-able N-central vulnerable to authentication bypass (CVE-2026-18577). Immediate patching is required.

Aug 3, 2026
SH-2026-144MediumOpen

Cisco FMC Hard-Coded Password Flaw (CVE-2026-20316): Attack Paths & Triage

A hard-coded password vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20316) allows unauthenticated low-privileged access.

Jul 29, 2026CVSS 5.3
SH-2026-143CriticalOpen

Analyzing CVE-2026-16812: Critical OS Command Injection in VeloCloud Orchestrator

CVE-2026-16812 is a maximum-severity OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem enabling remote host compromise.

Jul 27, 2026CVSS 10.0
SH-2026-142MediumOpen

FortiOS Patch Bypass (CVE-2025-68686) Exposes Persistence Vectors

CVE-2025-68686 allows remote attackers to bypass FortiOS patches for symbolic link persistence, requiring immediate remediation and forensic triage.

Jul 27, 2026CVSS 5.9
SH-2026-141CriticalOpen

Analyzing CVE-2026-50522: Critical Deserialization Risk in Microsoft SharePoint

Technical analysis of CVE-2026-50522, a critical 9.8 CVSS Microsoft SharePoint deserialization vulnerability, and how to defend your enterprise.

Jul 23, 2026CVSS 9.8
SH-2026-140CriticalOpen

Check Point SmartConsole Flaw Exposes Admin Tokens to Remote Attackers

A critical improper authentication vulnerability in Check Point SmartConsole (CVE-2026-16232) allows unauthenticated remote administrative access.

Jul 23, 2026CVSS 9.1
SH-2026-139HighOpen

Securing DD-WRT Devices Against Critical UPnP Buffer Overflow Vulnerability

A detailed analysis of CVE-2021-27137, a critical stack-based buffer overflow in DD-WRT's UPnP service, including risks and remediation steps.

Jul 23, 2026CVSS 8.1
SH-2026-138CriticalOpen

CVE-2026-0770: Critical RCE Vulnerability in Langflow AI Framework

A detailed security advisory on CVE-2026-0770, a critical remote code execution vulnerability in Langflow's untrusted control sphere handling.

Jul 23, 2026CVSS 9.8