> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
Two Parsers, One URL: The Interpretation-Conflict Bug Is Eating Authentication in 2026
Cisco SD-WAN, UniFi OS, Starlette and Clerk all fell to the same flaw this year: the component that decides who gets in and the component that decides where the request goes read the URL differently. Here is why it keeps happening and how to stop shipping it.
Zammad CVE-2026-102489 and CVE-2026-102490: Session Hijack to Root Chain Exploited in DIVD Breach
Two Zammad zero-days chain a session hijack into RCE and local root; DIVD says an autonomous AI agent used them to breach its network, CISA added both to KEV, and the root flaw reportedly has no patch.
GitLab AI Gateway CVE-2026-90970: Prompt Template Sandbox Escape Gives Command Execution
GitLab patches CVE-2026-90970, a CVSS 9.9 Jinja2 prompt-template sandbox escape in self-hosted AI Gateway that lets an authenticated Duo Agent Platform user run arbitrary commands on the host.
Dell Container Storage Modules: Two CVSS 10 Missing-Authentication Flaws Expose Kubernetes Storage Admin Credentials
Dell's DSA-2026-448 fixes two maximum-severity missing-authentication bugs in the CSM Authorization module that let unauthenticated attackers take over storage arrays behind Kubernetes clusters.
MikroTik RouterOS CVE-2026-84411: Pre-Auth Integer Underflow in Web Management Gives Root RCE
CISA's ICS advisory ICSA-26-272-06 flags a CVSS 9.8 pre-authentication integer underflow in the RouterOS web management service that a single crafted HTTP request can turn into root code execution or a crash.
Warlock Ransomware Crew Keeps Breaking In Through SharePoint, Hits Water and Telecom Operators
Symantec ties the China-linked Storm-2603 (Longlegs) crew to new Warlock ransomware intrusions at a water utility and a telecom, using SharePoint access, a vulnerable K7 driver, VS Code tunnels and SYSVOL deployment.
FortiMail CVE-2026-104286: Unauthenticated Path Traversal Exploited as Zero-Day
Fortinet confirms in-the-wild exploitation of CVE-2026-104286, a CVSS 9.8 path traversal in FortiMail that lets unauthenticated attackers write arbitrary files. Patches are not yet released; CISA set a October 4 deadline.
TeamViewer Patches Five High-Severity Flaws, Including Remote Session Access Control Bypass to RCE
TeamViewer bulletin TV-2026-1010 fixes five high-severity client and host flaws, led by CVE-2026-92370, a remote-session access control bypass that can lead to code execution. Update to 15.82.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Exploited
Cisco confirms in-the-wild exploitation of CVE-2026-76504, a CVSS 9.8 URL-encoding auth bypass that hands unauthenticated attackers admin API access on Catalyst SD-WAN Manager. No workaround; CISA added it to KEV.
CVE-2026-89775: KVM/arm64 Nested-Virtualization Bug Gives Guests Read-Write Access to Host Kernel Memory
A type-truncation bug in KVM/arm64's stage-1 page-table walk lets a guest keep a writable mapping to a freed host kernel page, enabling guest-to-host escape on ARM64 hosts with nested virtualization enabled.
Branch Target Reuse: New Spectre v2 Variant Leaks Linux Root Password Hash Through the cBPF JIT
VUSec's Branch Target Reuse abuses stale indirect-branch predictions over freed JIT memory to leak a root password hash from Linux in 3-5 minutes; kernel fixes for CVE-2026-64507 and CVE-2026-64508 are merged.
MemTensor MemOS Packages Backdoored with sckit, a Go Credential-Stealing Worm, on npm and PyPI
Malicious releases of MemTensor's MemOS OpenClaw plugin (npm) and MemoryOS (PyPI) deliver sckit, a cross-platform Go implant that steals 13 credential types and carries worm templates for npm, PyPI and GitHub Actions.
Cloudflare Containers Bug Let One Tenant Read Another Tenant's Disk Data
A misconfigured Linux dm-thin storage pool let any Cloudflare Workers Paid customer recover unzeroed residual disk blocks from other tenants' Containers, Sandboxes, and Browser Rendering instances — exposing SQLite databases, .env files, and credentials.
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
Two Malicious CPAN Modules Smuggle a Python Backdoor Inside a Fake Certificate File
Crypt::SelfCertificate and IO::Socket::SSL::SelfCertificate, two CPAN distributions for generating self-signed certs, shipped versions that hide obfuscated Python code inside a sample cert.pem and execute it as a remote-fetch loader.
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.