<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: HOL (Hashgraph Online)</title>
    <description>The latest articles on DEV Community by HOL (Hashgraph Online) (hol).</description>
    <link>https://dev.to/hol</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F12608%2Fcbc4252d-042e-4203-bcc5-f1a27d5b24e0.png</url>
      <title>DEV Community: HOL (Hashgraph Online)</title>
      <link>https://dev.to/hol</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/hol"/>
    <language>en</language>
    <item>
      <title>Cisco SD-WAN Manager admin API bypass hits CISA KEV</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Wed, 30 Sep 2026 17:18:42 +0000</pubDate>
      <link>https://dev.to/hol/cisco-sd-wan-manager-admin-api-bypass-hits-cisa-kev-4opg</link>
      <guid>https://dev.to/hol/cisco-sd-wan-manager-admin-api-bypass-hits-cisa-kev-4opg</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass-kev" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog today (2026-09-30).&lt;/strong&gt; Cisco Catalyst SD-WAN Manager has a hex/URI-encoding bug: an unauthenticated remote attacker who can reach the Manager can bypass the API session auth rule and land on the admin API. Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU this morning, rates it CVSS 3.1 base 9.8, and says PSIRT became aware of active exploitation in September 2026. There are no workarounds. Federal KEV due date is &lt;strong&gt;2026-10-03&lt;/strong&gt;. Forensic triage is &lt;strong&gt;Yes&lt;/strong&gt; under BOD 26-04. Known ransomware campaign use is &lt;strong&gt;Unknown&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This is the KEV follow-up to our same-day BREAKING write-up: &lt;a href="https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-76504-cisco-sd-wan-manager-auth-bypass-kev" rel="noopener noreferrer"&gt;Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)&lt;/a&gt;. That page still has the full operator detail. This page adds the CISA KEV clock (catalogVersion 2026.09.30, dateAdded 2026-09-30) and the federal triage due date. The HOL Guard &lt;a href="https://hol.org/guard/security/cves/CVE-2026-76504-cisco-catalyst-sd-wan-manager-system-account?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-76504-cisco-sd-wan-manager-auth-bypass-kev" rel="noopener noreferrer"&gt;evidence pack for CVE-2026-76504&lt;/a&gt; is the linked source record.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Cisco Catalyst SD-WAN Cloud Hosted (Cisco Managed)&lt;/strong&gt;: Cisco already shipped fixed Release 20.15.605. No customer action. Confirm status from Help in the service GUI.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;On-prem / customer-managed Managers already on a fixed build&lt;/strong&gt;: 20.9.10.1+, 20.12.8.2+, 20.15.6.1+, 20.18.4.1+, 26.1.2.1+, or 26.2.1+ on the matching train. Releases earlier than 20.9 must migrate to a fixed release.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Products Cisco did not list&lt;/strong&gt;: only Cisco Catalyst SD-WAN Manager is named in this advisory. Do not treat a random IOS-XE or Meraki advisory as coverage for 76504.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your Manager is internet-reachable on the management plane, treat it as exposed until the build is fixed. Cisco says the product is affected regardless of system configuration. Config flags do not carve you out of KEV.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;SD-WAN Manager's API session auth mishandles URI encoding (CWE-177). A crafted HTTP request can skip the rule that is supposed to keep unauthenticated callers off a specific API endpoint (Cisco ties this to &lt;code&gt;j_security_check&lt;/code&gt;). A successful exploit gives admin-user API access. Cisco Bug ID: CSCww79570. CISA's KEV short description matches: hex encoding vulnerability, unauthenticated remote attacker can access the affected system with admin privileges due to improper handling of URI encoding in an HTTP request.&lt;/p&gt;

&lt;p&gt;Cisco's Indicators of Compromise section shows URI-encoding a character inside that path (example: &lt;code&gt;%6a&lt;/code&gt; for &lt;code&gt;j&lt;/code&gt;). Encoding any one character in the request can be enough. Treat that as an example, not the only payload shape. Same-day KEV means the federal clock and BOD 26-04 forensic triage apply even if you already started patching from this morning's advisory.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not a local misconfiguration bug, and it is not limited to Managers that enabled some optional feature. It is also not an RCE advisory by name: the documented impact is unauthenticated admin API access. Network exposure reduction is a temporary mitigation for on-prem only, not a fix. KEV does not invent a new bug; it marks this CVE as known-exploited with a due date.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check
&lt;/h2&gt;

&lt;p&gt;Confirm the Manager software version from the GUI Help panel or your inventory against the fixed table below. Then audit the logs Cisco names for URI-encoded &lt;code&gt;j_security_check&lt;/code&gt; hits and &lt;code&gt;viptela-reserved-&lt;/code&gt; system account activity from unknown IPs.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# service-proxy access log (example path from the advisory)&lt;/span&gt;
&lt;span class="c"&gt;# /var/log/nms/containers/service-proxy/serviceproxy-access.log&lt;/span&gt;
&lt;span class="c"&gt;# Look for URI-encoded j_security_check from unknown sources, e.g.:&lt;/span&gt;
&lt;span class="c"&gt;# POST /%6a_security_check HTTP/1.1  200&lt;/span&gt;

&lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-E&lt;/span&gt; &lt;span class="s1"&gt;'j_security_check|%6[aA]_security_check|%[0-9A-Fa-f]{2}_security_check'&lt;/span&gt;   /var/log/nms/containers/service-proxy/serviceproxy-access.log
vManage server log
/var/log/nms/vmanage-server.log
Look &lt;span class="k"&gt;for &lt;/span&gt;j_security_check stored &lt;span class="k"&gt;for &lt;/span&gt;viptela-reserved- &lt;span class="nb"&gt;users&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Cisco notes these IOC patterns can also appear in normal operations, so compare against your baseline. For suspected compromise, collect &lt;code&gt;request admin-tech&lt;/code&gt; from the Manager and open a Severity 3 TAC case with CVE-2026-76504 in the title. Federal agencies under BOD 26-04 also owe forensic triage by the KEV due date.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade on-prem / customer-managed Cisco Catalyst SD-WAN Manager to the first fixed release on your train (or later on that train):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Earlier than 20.9: migrate to a fixed release&lt;/li&gt;
&lt;li&gt;  20.9 → &lt;code&gt;20.9.10.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.12 → &lt;code&gt;20.12.8.2&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.15 → &lt;code&gt;20.15.6.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.18 → &lt;code&gt;20.18.4.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  26.1 → &lt;code&gt;26.1.2.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  26.2 → &lt;code&gt;26.2.1&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Use the Catalyst SD-WAN Control Component Compatibility Matrix and the Cisco Catalyst SD-WAN Upgrade Matrix before you cut over. There is no software workaround. For on-prem Managers that must stay online during the window, Cisco's temporary mitigation is to keep the management plane off untrusted networks: put Control Components behind a filtering device, allow only known trusted hosts, and follow the Cisco Catalyst SD-WAN Hardening Guide. That mitigation is already deployed for Cloud Hosted environments. Federal due date under this KEV row is &lt;strong&gt;2026-10-03&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; (CVE-2026-76504, dateAdded 2026-09-30, dueDate 2026-10-03, catalogVersion 2026.09.30, BOD 26-04, forensic triage Yes, ransomware Unknown)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU" rel="noopener noreferrer"&gt;Cisco Security Advisory: cisco-sa-sdwan-webauth-xr8beuuU (CVE-2026-76504)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-76504-cisco-sd-wan-manager-auth-bypass-kev" rel="noopener noreferrer"&gt;HOL BREAKING write-up (same-day advisory)&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>cisco</category>
      <category>sdwan</category>
      <category>catalystsdwanmanager</category>
    </item>
    <item>
      <title>BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Wed, 30 Sep 2026 13:50:32 +0000</pubDate>
      <link>https://dev.to/hol/breaking-cisco-sd-wan-manager-admin-api-open-without-a-login-cve-2026-76504-224i</link>
      <guid>https://dev.to/hol/breaking-cisco-sd-wan-manager-admin-api-open-without-a-login-cve-2026-76504-224i</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-76504-cisco-sd-wan-manager-auth-bypass" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cisco published advisory cisco-sa-sdwan-webauth-xr8beuuU today (2026-09-30) for CVE-2026-76504.&lt;/strong&gt; An unauthenticated remote attacker who can reach Cisco Catalyst SD-WAN Manager can bypass the API session auth rule with a URI-encoded request and land on the API as the admin user. Cisco rates it CVSS 3.1 base 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The bug is CWE-177 (Improper Handling of URL Encoding). There are no workarounds. The advisory says the product is affected regardless of system configuration. Cisco PSIRT became aware of active exploitation in September 2026. Fixed trains: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, and 26.2.1. Cloud Hosted (Cisco Managed) is already on 20.15.605 with no customer action. This page is the operator write-up from the Cisco Security Advisory. The HOL Guard &lt;a href="https://hol.org/guard/security/cves/CVE-2026-76504-cisco-catalyst-sd-wan-manager-system-account?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-76504-cisco-sd-wan-manager-auth-bypass" rel="noopener noreferrer"&gt;evidence pack for CVE-2026-76504&lt;/a&gt; is the linked source record.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Cisco Catalyst SD-WAN Cloud Hosted (Cisco Managed)&lt;/strong&gt;: Cisco already shipped fixed Release 20.15.605. No user action is required. Check status or version from Help in the service GUI.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;On-prem / customer-managed Managers already on a fixed build&lt;/strong&gt;: 20.9.10.1+, 20.12.8.2+, 20.15.6.1+, 20.18.4.1+, 26.1.2.1+, or 26.2.1+ on the matching train. Releases earlier than 20.9 must migrate to a fixed release.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Products Cisco did not list&lt;/strong&gt;: only Cisco Catalyst SD-WAN Manager is called out as vulnerable in this advisory.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your Manager is internet-reachable on the management plane, treat it as exposed until the build is fixed. Config flags do not carve you out: Cisco says the product is affected regardless of system configuration.&lt;/p&gt;

&lt;h2&gt;
  
  
  What broke
&lt;/h2&gt;

&lt;p&gt;SD-WAN Manager's API session auth management mishandles URI encoding. A crafted HTTP request can skip the rule that is supposed to keep unauthenticated callers off a specific API endpoint (the advisory ties this to &lt;code&gt;j_security_check&lt;/code&gt;). A successful exploit gives the attacker admin-user API access. Cisco Bug ID: CSCww79570. The vulnerability was found while resolving a Cisco TAC support case.&lt;/p&gt;

&lt;p&gt;Cisco's Indicators of Compromise section shows the pattern as URI-encoding a character inside that path (example: &lt;code&gt;%6a&lt;/code&gt; for &lt;code&gt;j&lt;/code&gt;). Encoding any one character in the request can be enough. Treat that as an example, not the only payload shape.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not a local-only misconfiguration bug, and it is not limited to Managers that enabled some optional feature. Cisco states the product is affected regardless of configuration. It is also not an RCE advisory by name: the documented impact is unauthenticated admin API access. Cisco does state active exploitation in September 2026, and there are no workarounds that fix the bug itself. Network exposure reduction is a temporary mitigation for on-prem only.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check
&lt;/h2&gt;

&lt;p&gt;Confirm the Manager software version from the GUI Help panel or your inventory against the fixed table below. Then audit the logs Cisco names for URI-encoded &lt;code&gt;j_security_check&lt;/code&gt; hits and &lt;code&gt;viptela-reserved-&lt;/code&gt; system account activity from unknown IPs.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# service-proxy access log (example path from the advisory)&lt;/span&gt;
&lt;span class="c"&gt;# /var/log/nms/containers/service-proxy/serviceproxy-access.log&lt;/span&gt;
&lt;span class="c"&gt;# Look for URI-encoded j_security_check from unknown sources, e.g.:&lt;/span&gt;
&lt;span class="c"&gt;# POST /%6a_security_check HTTP/1.1  200&lt;/span&gt;

&lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-E&lt;/span&gt; &lt;span class="s1"&gt;'j_security_check|%6[aA]_security_check|%[0-9A-Fa-f]{2}_security_check'&lt;/span&gt;   /var/log/nms/containers/service-proxy/serviceproxy-access.log
vManage server log
/var/log/nms/vmanage-server.log
Look &lt;span class="k"&gt;for &lt;/span&gt;j_security_check stored &lt;span class="k"&gt;for &lt;/span&gt;viptela-reserved- &lt;span class="nb"&gt;users&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Cisco notes these IOC patterns can also appear in normal operations, so compare against your baseline. For suspected compromise, collect &lt;code&gt;request admin-tech&lt;/code&gt; from the Manager and open a Severity 3 TAC case with CVE-2026-76504 in the title.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade on-prem / customer-managed Cisco Catalyst SD-WAN Manager to the first fixed release on your train (or later on that train):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Earlier than 20.9: migrate to a fixed release&lt;/li&gt;
&lt;li&gt;  20.9 → &lt;code&gt;20.9.10.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.12 → &lt;code&gt;20.12.8.2&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.15 → &lt;code&gt;20.15.6.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  20.18 → &lt;code&gt;20.18.4.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  26.1 → &lt;code&gt;26.1.2.1&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  26.2 → &lt;code&gt;26.2.1&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Use the Catalyst SD-WAN Control Component Compatibility Matrix and the Cisco Catalyst SD-WAN Upgrade Matrix before you cut over. There is no software workaround. For on-prem Managers that must stay online during the window, Cisco's temporary mitigation is to keep the management plane off untrusted networks: put Control Components behind a filtering device, allow only known trusted hosts, and follow the Cisco Catalyst SD-WAN Hardening Guide. That mitigation is already deployed for Cloud Hosted environments.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU" rel="noopener noreferrer"&gt;Cisco Security Advisory: cisco-sa-sdwan-webauth-xr8beuuU (CVE-2026-76504)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://hol.org/guard/security/cves/CVE-2026-76504-cisco-catalyst-sd-wan-manager-system-account?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-76504-cisco-sd-wan-manager-auth-bypass" rel="noopener noreferrer"&gt;HOL Guard evidence pack: CVE-2026-76504&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>cisco</category>
      <category>sdwan</category>
      <category>catalystsdwanmanager</category>
    </item>
    <item>
      <title>Unsloth RCE: malicious Hugging Face model config.json injects code</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Mon, 28 Sep 2026 15:29:07 +0000</pubDate>
      <link>https://dev.to/hol/unsloth-rce-malicious-hugging-face-model-configjson-injects-code-1oie</link>
      <guid>https://dev.to/hol/unsloth-rce-malicious-hugging-face-model-configjson-injects-code-1oie</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-93348-unsloth-zoo-code-injection-config-json" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  Unsloth RCE: malicious Hugging Face model config.json injects code
&lt;/h1&gt;

&lt;p&gt;If you fine-tune or serve models with Unsloth and you load weights from Hugging Face (or any path that ships a &lt;code&gt;config.json&lt;/code&gt;), a nested &lt;code&gt;model_type&lt;/code&gt; string can turn into Python that Unsloth &lt;code&gt;exec&lt;/code&gt;s. Same-day record &lt;strong&gt;CVE-2026-93348&lt;/strong&gt; (CVSS 8.6 HIGH, CWE-94) covers Unsloth Zoo &lt;code&gt;&amp;gt;=2025.9.9&lt;/code&gt; and &lt;code&gt;&amp;lt;2026.8.14&lt;/code&gt;, as pulled in by Unsloth &lt;code&gt;&amp;gt;=2025.9.9&lt;/code&gt; and &lt;code&gt;&amp;lt;2026.8.20&lt;/code&gt;. The maintainer fix is already on PyPI: upgrade &lt;code&gt;unsloth-zoo&lt;/code&gt; to &lt;code&gt;2026.8.14+&lt;/code&gt; and &lt;code&gt;unsloth&lt;/code&gt; to &lt;code&gt;2026.8.20+&lt;/code&gt; (current wheels are newer). This is the operator write-up from the merged Unsloth Zoo patch and the VulnCheck advisory. The HOL Guard evidence pack is at &lt;a href="https://hol.org/guard/security/cves/CVE-2026-93348-unsloth-zoo-code-injection-via-modeltype-in?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-93348-unsloth-zoo-code-injection-config-json" rel="noopener noreferrer"&gt;/guard/security/cves/CVE-2026-93348-unsloth-zoo-code-injection-via-modeltype-in&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;p&gt;You can ignore this ticket if any of these hold:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  You do not install or import &lt;code&gt;unsloth&lt;/code&gt; / &lt;code&gt;unsloth-zoo&lt;/code&gt; at all.&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;pip show unsloth-zoo&lt;/code&gt; reports &lt;code&gt;2026.8.14&lt;/code&gt; or newer &lt;strong&gt;and&lt;/strong&gt; &lt;code&gt;pip show unsloth&lt;/code&gt; reports &lt;code&gt;2026.8.20&lt;/code&gt; or newer (or you never pin the older train).&lt;/li&gt;
&lt;li&gt;  Your training / inference path never calls Unsloth's transformers compile / load helpers that read &lt;code&gt;model_type&lt;/code&gt; from a downloaded config (plain &lt;code&gt;transformers&lt;/code&gt; without Unsloth is a different stack).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Hugging Face Hub hosting alone is not the bug. The issue is what Unsloth does with a config field after you choose to load that model.&lt;/p&gt;

&lt;h2&gt;
  
  
  What broke
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;get_transformers_model_type()&lt;/code&gt; in &lt;code&gt;unsloth_zoo/hf_utils.py&lt;/code&gt; walked nested model configs and collected &lt;code&gt;model_type&lt;/code&gt; after a light normalize that rewrote &lt;code&gt;-&lt;/code&gt;, &lt;code&gt;/&lt;/code&gt;, and &lt;code&gt;.&lt;/code&gt; to &lt;code&gt;_&lt;/code&gt;. It did not enforce an &lt;code&gt;[a-z0-9_]&lt;/code&gt; allowlist. A newline (or other injection) in a nested &lt;code&gt;model_type&lt;/code&gt; inside a malicious model's &lt;code&gt;config.json&lt;/code&gt; survived into the string that &lt;code&gt;unsloth_compile_transformers()&lt;/code&gt; built for an import, then handed to &lt;code&gt;exec()&lt;/code&gt;. The same string also shaped compiled cache filenames via &lt;code&gt;create_new_function&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Merged Unsloth Zoo PR &lt;a href="https://github.com/unslothai/unsloth-zoo/pull/1083" rel="noopener noreferrer"&gt;#1083&lt;/a&gt; (follow-up &lt;a href="https://github.com/unslothai/unsloth-zoo/pull/1108" rel="noopener noreferrer"&gt;#1108&lt;/a&gt;) and the Unsloth bump commit &lt;a href="https://github.com/unslothai/unsloth/commit/92ee0207a38ebc8af1a0e678aa92d7e7d901ea0d" rel="noopener noreferrer"&gt;92ee020&lt;/a&gt; close that path. Credit for the report: Ariel Fogel (afogel) of Pillar Security, per the VulnCheck advisory.&lt;/p&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip show unsloth-zoo unsloth | egrep &lt;span class="s1"&gt;'^(Name|Version):'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Treat any &lt;code&gt;unsloth-zoo&lt;/code&gt; below &lt;code&gt;2026.8.14&lt;/code&gt; or any &lt;code&gt;unsloth&lt;/code&gt; below &lt;code&gt;2026.8.20&lt;/code&gt; (on the affected train starting at &lt;code&gt;2025.9.9&lt;/code&gt;) as vulnerable until upgraded. If those packages are absent, you are out of scope for this CVE.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not an unauthenticated internet worm and not a Hub-wide remote exploit against every Hugging Face user. CVSS 4.0 marks &lt;code&gt;UI:P&lt;/code&gt;: someone (or a pipeline) has to load a malicious model so Unsloth's compile path runs as that user. Impact is still full code execution as the loading account once that happens, which is why the score sits at 8.6 HIGH.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-U&lt;/span&gt; &lt;span class="s2"&gt;"unsloth-zoo&amp;gt;=2026.8.14"&lt;/span&gt; &lt;span class="s2"&gt;"unsloth&amp;gt;=2026.8.20"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or bump the same floors in your lockfile / image and redeploy. Re-run the &lt;code&gt;pip show&lt;/code&gt; check above. Prefer pinned known-good model revisions from authors you trust; treat unknown &lt;code&gt;config.json&lt;/code&gt; trees like untrusted code when they feed a compile path that used to &lt;code&gt;exec&lt;/code&gt; interpolated imports.&lt;/p&gt;

&lt;p&gt;What the patch actually changed (so you can sanity-check a backported fork):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Allowlist &lt;code&gt;model_type&lt;/code&gt; with &lt;code&gt;[a-z0-9_]+&lt;/code&gt; immediately after the existing normalize in &lt;code&gt;hf_utils.py&lt;/code&gt; (single choke point for Unsloth loaders).&lt;/li&gt;
&lt;li&gt;  Replace &lt;code&gt;exec(f"import {model_location}")&lt;/code&gt; with &lt;code&gt;importlib.import_module&lt;/code&gt; in the compiler path (keeping a deliberate &lt;code&gt;import transformers&lt;/code&gt; for downstream &lt;code&gt;eval&lt;/code&gt; call sites that still expect that binding).&lt;/li&gt;
&lt;li&gt;  Stop string-&lt;code&gt;exec&lt;/code&gt; assignment in &lt;code&gt;empty_model.set_additional_modules&lt;/code&gt; in favor of a dotted path walk.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;PR #1083 reports the allowlist accepts every legitimate &lt;code&gt;model_type&lt;/code&gt; shipped in the tested transformers matrices and rejects newline / quote / path-injection style payloads.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://www.vulncheck.com/advisories/unsloth-zoo-code-injection-via-model-type-in-config-json" rel="noopener noreferrer"&gt;VulnCheck advisory: Unsloth Zoo code injection via model_type in config.json&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/unslothai/unsloth-zoo/pull/1083" rel="noopener noreferrer"&gt;unsloth-zoo PR #1083 (merged)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/unslothai/unsloth-zoo/pull/1108" rel="noopener noreferrer"&gt;unsloth-zoo PR #1108 (follow-up)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/unslothai/unsloth/commit/92ee0207a38ebc8af1a0e678aa92d7e7d901ea0d" rel="noopener noreferrer"&gt;unsloth bump commit 92ee020&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>unsloth</category>
      <category>unslothzoo</category>
      <category>huggingface</category>
    </item>
    <item>
      <title>BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Sun, 27 Sep 2026 16:45:55 +0000</pubDate>
      <link>https://dev.to/hol/breaking-unauthenticated-netscaler-rce-hits-every-appliance-cve-2026-88771-503m</link>
      <guid>https://dev.to/hol/breaking-unauthenticated-netscaler-rce-hits-every-appliance-cve-2026-88771-503m</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-88771-netscaler-unauthenticated-rce" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
&lt;/h1&gt;

&lt;p&gt;Citrix published security bulletin &lt;a href="https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin" rel="noopener noreferrer"&gt;CTX697096&lt;/a&gt; on 2026-09-27 for eight NetScaler ADC / NetScaler Gateway flaws. The lead issue is &lt;strong&gt;CVE-2026-88771&lt;/strong&gt;: unauthenticated remote code execution from improper input validation on every customer-managed NetScaler ADC and Gateway deployment, including default configuration. No extra feature has to be turned on. Citrix rates it CVSS v4.0 9.5 and states that exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated deployments have been observed. Fixed builds are &lt;code&gt;14.1-73.37&lt;/code&gt;, &lt;code&gt;13.1-64.23&lt;/code&gt;, &lt;code&gt;14.1-73.37&lt;/code&gt; FIPS, and &lt;code&gt;13.1.37.279&lt;/code&gt; FIPS/NDcPP. This is the operator write-up from CTX697096 and the CVE AWG records. The HOL Guard evidence pack for the lead CVE is at &lt;a href="https://hol.org/guard/security/cves/CVE-2026-88771?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-88771-netscaler-unauthenticated-rce" rel="noopener noreferrer"&gt;/guard/security/cves/CVE-2026-88771&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;p&gt;Skip the pager only if one of these is true:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Cloud Software Group already runs the appliance for you. CTX697096 applies to &lt;strong&gt;customer-managed&lt;/strong&gt; NetScaler ADC and NetScaler Gateway only. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by CSG.&lt;/li&gt;
&lt;li&gt;  Every customer-managed ADC/Gateway instance you own is already on &lt;code&gt;14.1-73.37+&lt;/code&gt;, &lt;code&gt;13.1-64.23+&lt;/code&gt;, &lt;code&gt;14.1-73.37&lt;/code&gt; FIPS+, or &lt;code&gt;13.1.37.279&lt;/code&gt; FIPS/NDcPP+.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Do not confuse that cloud carve-out with Secure Private Access Hybrid. Citrix says Secure Private Access Hybrid deployments that use NetScaler instances &lt;strong&gt;are&lt;/strong&gt; affected; you still upgrade those appliances to the builds above.&lt;/p&gt;

&lt;p&gt;Sibling preconditions differ. CVE-2026-88772 needs DTLS enabled (on by default for VPN vServers unless you set &lt;code&gt;-dtls OFF&lt;/code&gt;). CVE-2026-88775 needs Gateway or AAA. CVE-2026-88776 needs an Oracle LB vServer. CVE-2026-88771 does not: every default ADC/Gateway is in.&lt;/p&gt;

&lt;h2&gt;
  
  
  What broke
&lt;/h2&gt;

&lt;p&gt;CTX697096 clusters eight CVEs on the same upgrade train. Treat them as one patch event.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88771&lt;/strong&gt; (CVSS 9.5): unauthenticated RCE via improper input validation. All NetScaler ADC and Gateway deployments. Default configuration. No additional feature required.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88772&lt;/strong&gt; (CVSS 9.5): memory overflow to RCE or DoS when DTLS is enabled. DTLS is enabled by default on VPN vServers.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88773&lt;/strong&gt; (CVSS 9.3): HTTP request smuggling when HTTP is configured.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88774&lt;/strong&gt; (CVSS 7.0): feature-policy bypass via HTTP URL-based policy expressions.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88775&lt;/strong&gt; (CVSS 8.8): memory overflow / DoS on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88776&lt;/strong&gt; (CVSS 8.8): memory overflow / DoS on Oracle-type LB virtual servers.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88777&lt;/strong&gt; (CVSS 8.8): memory overflow / DoS on LB/CS or CGNAT-LSN/NAT64 with certain non-HTTP L7 features (FTP, RTSP, DNS64, NAT64, and related patterns in the bulletin).&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;CVE-2026-88778&lt;/strong&gt; (CVSS 8.8): TCP Initial Sequence Number prediction when TCP is configured and Enhanced ISN Generation is disabled.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Affected supported trains before the fixed builds: NetScaler ADC/Gateway 14.1 before &lt;code&gt;14.1-73.37&lt;/code&gt;, 13.1 before &lt;code&gt;13.1-64.23&lt;/code&gt;, ADC FIPS before &lt;code&gt;14.1-73.37&lt;/code&gt; FIPS, and ADC FIPS/NDcPP before &lt;code&gt;13.1.37.279&lt;/code&gt;. Credit in the bulletin: Michael Tucker, Chew Keong Tan, and Alex Bernier (JPMorgan Chase XOR Team), and Maxim Suhanov.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not a Gateway-only or AAA-only story. CVE-2026-88771 needs no special feature and hits every customer-managed NetScaler ADC and Gateway on the affected builds, including default config. It is also not limited to appliances you personally racked: Secure Private Access Hybrid NetScaler instances are in scope. Citrix-managed cloud and Adaptive Auth are the carve-out, not Hybrid SPA. CISA KEV caught up on 2026-09-27 for CVE-2026-88771 and CVE-2026-88772 (due 2026-09-30, forensic triage Yes). Citrix already stated exploits of both were observed on unmitigated deployments; treat the KEV rows plus CTX697096 as the operational clock.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check
&lt;/h2&gt;

&lt;p&gt;Confirm the build the appliance is actually running:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;show ns version
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Anything on 14.1 below &lt;code&gt;14.1-73.37&lt;/code&gt;, on 13.1 below &lt;code&gt;13.1-64.23&lt;/code&gt;, on 14.1-FIPS below &lt;code&gt;14.1-73.37&lt;/code&gt; FIPS, or on 13.1-FIPS/NDcPP below &lt;code&gt;13.1.37.279&lt;/code&gt; is still in the RCE window for CVE-2026-88771.&lt;/p&gt;

&lt;p&gt;For CVE-2026-88772 (DTLS), inspect VPN and DTLS virtual servers. Patterns from CTX697096:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight cisco_ios"&gt;&lt;code&gt;&lt;span class="k"&gt;# DTLS&lt;/span&gt; on by default (vulnerable precondition for 88772)
&lt;span class="k"&gt;add&lt;/span&gt; vpn vserver vpn1 SSL &lt;span class="m"&gt;10.0.0.0&lt;/span&gt; 443 -Listenpolicy NONE

&lt;span class="k"&gt;DTLS&lt;/span&gt; explicitly off (88772 precondition not met)
&lt;span class="k"&gt;add&lt;/span&gt; vpn vserver vpn1 SSL &lt;span class="m"&gt;10.0.0.0&lt;/span&gt; 443 -dtls OFF -Listenpolicy NONE
&lt;span class="k"&gt;explicit&lt;/span&gt; DTLS vServers (precondition met)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For CVE-2026-88778, confirm Enhanced ISN Generation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;show ns tcpparam | &lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="s2"&gt;"Enhanced ISN Generation"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If that returns &lt;code&gt;Enhanced ISN Generation: DISABLED&lt;/code&gt; and you have TCP-family virtual servers, apply the Enhanced ISN change from the NetScaler TCP configuration docs in addition to the build upgrade. The bulletin points at &lt;a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation" rel="noopener noreferrer"&gt;Enhanced ISN Generation&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade customer-managed NetScaler ADC and NetScaler Gateway to one of these builds (or later on the same train):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  NetScaler ADC / Gateway &lt;code&gt;14.1-73.37&lt;/code&gt;+&lt;/li&gt;
&lt;li&gt;  NetScaler ADC / Gateway &lt;code&gt;13.1-64.23&lt;/code&gt;+ (13.1 train)&lt;/li&gt;
&lt;li&gt;  NetScaler ADC FIPS &lt;code&gt;14.1-73.37&lt;/code&gt; FIPS+&lt;/li&gt;
&lt;li&gt;  NetScaler ADC FIPS / NDcPP &lt;code&gt;13.1.37.279&lt;/code&gt;+&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pull the builds from Citrix support, stage in a maintenance window that matches your HA / GSLB cutover, then re-check with &lt;code&gt;show ns version&lt;/code&gt;. For CVE-2026-88778, also enable Enhanced ISN Generation per the TCP configuration doc above. There is no feature-flag substitute for the CVE-2026-88771 fix: every default deployment is in scope until the build is current.&lt;/p&gt;

&lt;p&gt;If you run Secure Private Access Hybrid on NetScaler instances, upgrade those instances to the same builds. Do not assume the Citrix-managed cloud carve-out covers them.&lt;/p&gt;

&lt;h2&gt;
  
  
  CISA KEV (added 2026-09-27)
&lt;/h2&gt;

&lt;p&gt;CISA added &lt;strong&gt;CVE-2026-88771&lt;/strong&gt; and &lt;strong&gt;CVE-2026-88772&lt;/strong&gt; (both already covered in this NetScaler cluster write-up) to the Known Exploited Vulnerabilities catalog on &lt;strong&gt;2026-09-27&lt;/strong&gt; (catalog version 2026.09.27). Federal and BOD 26-04 covered operators have until &lt;strong&gt;2026-09-30&lt;/strong&gt;. Both KEV rows require &lt;strong&gt;forensic triage&lt;/strong&gt; (Yes). Ransomware use is listed as Unknown. Citrix already stated exploits of both CVEs were observed on unmitigated deployments; the KEV listing is the federal must-patch clock on the same upgrade train, not a new technical finding. Siblings CVE-2026-88773 through CVE-2026-88778 are not in the 2026-09-27 KEV batch.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88771" rel="noopener noreferrer"&gt;CISA KEV: CVE-2026-88771 (added 27 Sep 2026, due 30 Sep 2026, forensic triage Yes)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772" rel="noopener noreferrer"&gt;CISA KEV: CVE-2026-88772 (added 27 Sep 2026, due 30 Sep 2026, forensic triage Yes)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" rel="noopener noreferrer"&gt;CISA BOD 26-04 Prioritizing Security Updates Based on Risk&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html" rel="noopener noreferrer"&gt;Citrix CTX694799: steps if NetScaler ADC is suspected compromised&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://support.citrix.com/external/article/CTX697096/netscaler-adc-and-netscaler-gateway-security-bulletin" rel="noopener noreferrer"&gt;Citrix CTX697096: NetScaler ADC and NetScaler Gateway security bulletin&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://docs.netscaler.com/en-us/citrix-adc/current-release/system/tcp-configurations.html#enhanced-isn-generation" rel="noopener noreferrer"&gt;NetScaler TCP configurations: Enhanced ISN Generation&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://hol.org/guard/security/cves/CVE-2026-88771?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-88771-netscaler-unauthenticated-rce" rel="noopener noreferrer"&gt;HOL Guard evidence pack: CVE-2026-88771&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>netscaler</category>
      <category>citrix</category>
      <category>rce</category>
    </item>
    <item>
      <title>WordPress page template include hits CISA KEV</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Fri, 25 Sep 2026 20:22:34 +0000</pubDate>
      <link>https://dev.to/hol/wordpress-page-template-include-hits-cisa-kev-114a</link>
      <guid>https://dev.to/hol/wordpress-page-template-include-hits-cisa-kev-114a</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-87902-wordpress-core-page-template-lfi-kev" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog today (2026-09-25).&lt;/strong&gt; WordPress Core has an unauthenticated path traversal in page-template resolution: an attacker can make &lt;code&gt;get_page_template()&lt;/code&gt; include a chosen readable local &lt;code&gt;.php&lt;/code&gt; file outside the active theme directories. When the theme and PHP environment preconditions line up, that local file inclusion becomes remote code execution. GHSA-7hp8-65ch-5whp rates it critical (CVSS 4.0 9.2). Federal KEV due date is 2026-09-28. Forensic triage is Yes under BOD 26-04. Known ransomware campaign use is Unknown.&lt;/p&gt;

&lt;p&gt;WordPress shipped the fix in 7.1.2 on 2026-09-22 and backported it through every supported branch back to 4.7. Patchstack reports probing hours after the patch, then active attempts that include &lt;code&gt;pearcmd.php&lt;/code&gt; and write PHP to disk. This page is the operator write-up from the GHSA, the WordPress 7.1.2 release, CISA KEV, and Patchstack. The HOL Guard &lt;a href="https://hol.org/guard/security/cves/CVE-2026-87902?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-87902-wordpress-core-page-template-lfi-kev" rel="noopener noreferrer"&gt;evidence pack for CVE-2026-87902&lt;/a&gt; is the linked source record.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;Unauthenticated requests can abuse page-template resolution so WordPress includes a local &lt;code&gt;.php&lt;/code&gt; the attacker picks, as long as that file is readable by the web server. The GHSA names two preconditions that turn LFI into conditional RCE:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Theme layout:&lt;/strong&gt; the active child or parent theme has a top-level directory whose name starts with &lt;code&gt;page-&lt;/code&gt; (for example &lt;code&gt;page-templates&lt;/code&gt;). That hits legacy Twenty Twelve and Twenty Fourteen, plus popular third-party themes such as Neve, Hestia, and Sydney.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Readable target:&lt;/strong&gt; a chosen local &lt;code&gt;.php&lt;/code&gt; exists on disk. The well-known PEAR &lt;code&gt;pearcmd.php&lt;/code&gt; path is the practical RCE transition when &lt;code&gt;register_argc_argv&lt;/code&gt; is On. The official &lt;code&gt;php&lt;/code&gt; Docker image is affected, and default cPanel with PHP prior to 8.5 is affected.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Affected trains run from WordPress 4.7.0 through 7.1.1. Fixed builds: &lt;code&gt;7.1.2&lt;/code&gt;, &lt;code&gt;7.0.6&lt;/code&gt;, &lt;code&gt;6.9.9&lt;/code&gt;, &lt;code&gt;6.8.10&lt;/code&gt;, and matching backports on every branch down to &lt;code&gt;4.7.37&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;WordPress.com and hosts already on fixed builds&lt;/strong&gt; for your branch (7.1.2 or the backport listed for your major).&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Themes without a top-level &lt;code&gt;page-*&lt;/code&gt; directory&lt;/strong&gt; for the LFI-to-RCE path described in the GHSA. Upgrade anyway; the core sink is still patched for a reason.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Installs where no readable attacker-chosen &lt;code&gt;.php&lt;/code&gt; exists&lt;/strong&gt; (and PEAR / &lt;code&gt;register_argc_argv&lt;/code&gt; is not available). That lowers immediate RCE odds; it does not cancel the KEV clock or the probing.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;The earlier WordPress comment XSS story&lt;/strong&gt; (CVE-2026-93485 / 7.1.1). Different bug, different fix train. Do not treat a 7.1.1 bump as coverage for 87902.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;

&lt;p&gt;Print the WordPress core version and compare it to the patched build for your branch:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# WP-CLI&lt;/span&gt;
wp core version
&lt;span class="c"&gt;# or Dashboard → Updates, look for 7.1.2 (or your branch patch: 7.0.6, 6.9.9, 6.8.10, … back to 4.7.37)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Anything below the fixed build on that train is still open for this KEV row. If you run Docker &lt;code&gt;php&lt;/code&gt; or cPanel PHP &amp;lt; 8.5 with PEAR present, treat the upgrade as urgent even when you think the theme is “safe.”&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade WordPress Core to &lt;strong&gt;7.1.2&lt;/strong&gt;, or to the security backport on your current major:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;wp core update &lt;span class="nt"&gt;--version&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;7.1.2
&lt;span class="c"&gt;# or update through Dashboard → Updates / your host’s managed WordPress channel&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Branch matrix from GHSA-7hp8-65ch-5whp (vulnerable → fixed): 7.1.0–7.1.1 → 7.1.2; 7.0.0–7.0.5 → 7.0.6; 6.9.0–6.9.8 → 6.9.9; 6.8.0–6.8.9 → 6.8.10; continuing with matching patches on every branch back through 4.7.37. Prefer the path you already use (WP-CLI, dashboard, host panel). After the update, re-run &lt;code&gt;wp core version&lt;/code&gt;. Federal agencies under BOD 26-04 also owe forensic triage; KEV due date is 2026-09-28.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not unauthenticated RCE on every default WordPress install with zero preconditions. It is unauthenticated local file inclusion with conditional RCE when the theme has a &lt;code&gt;page-*&lt;/code&gt; top-level directory and a readable target such as &lt;code&gt;pearcmd.php&lt;/code&gt; is available. Still: CISA KEV today, Patchstack seeing pearcmd write-to-disk attempts, and a three-day federal due date.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp" rel="noopener noreferrer"&gt;GHSA-7hp8-65ch-5whp (WordPress Core)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://wordpress.org/news/2026/09/wordpress-7-1-2-release/" rel="noopener noreferrer"&gt;WordPress 7.1.2 release&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; (CVE-2026-87902, dateAdded 2026-09-25, dueDate 2026-09-28, BOD 26-04)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/" rel="noopener noreferrer"&gt;Patchstack: probing hours after the patch / pearcmd write attempts&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-87902" rel="noopener noreferrer"&gt;NVD CVE-2026-87902&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>wordpress</category>
      <category>lfi</category>
      <category>rce</category>
    </item>
    <item>
      <title>SharePoint code injection hits CISA KEV</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Fri, 25 Sep 2026 15:45:29 +0000</pubDate>
      <link>https://dev.to/hol/sharepoint-code-injection-hits-cisa-kev-3910</link>
      <guid>https://dev.to/hol/sharepoint-code-injection-hits-cisa-kev-3910</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-65660-microsoft-sharepoint-code-injection-kev" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CISA added CVE-2026-65660 to the Known Exploited Vulnerabilities catalog today (2026-09-25).&lt;/strong&gt; Microsoft published the SharePoint Server Remote Code Execution row in the August 2026 security update (2026-08-11). Impact is Remote Code Execution via code injection (CWE-94). Severity is Important, CVSS 3.1 base 8.8 (&lt;code&gt;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&lt;/code&gt;). Federal KEV due date is 2026-09-28. Forensic triage is marked Yes under BOD 26-04. Known ransomware campaign use is Unknown. MSRC still lists &lt;code&gt;exploited: No&lt;/code&gt; on the advisory; CISA's KEV listing is the later exploitation signal. Do not treat MSRC's August wording as a clean bill of health after today.&lt;/p&gt;

&lt;p&gt;This is the operator write-up from MSRC CVE-2026-65660, the August 2026 SharePoint KBs, CISA KEV catalogVersion 2026.09.25, and NVD. The HOL Guard evidence pack for this CVE, when it lands, is the &lt;a href="https://hol.org/guard/security/cves/CVE-2026-65660?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-65660-microsoft-sharepoint-code-injection-kev" rel="noopener noreferrer"&gt;linked source record&lt;/a&gt;; this page is the fix-first summary.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;MSRC rates this Important Remote Code Execution. An authenticated attacker with low-level access can send a specially crafted request and execute code on the SharePoint server. User interaction is not required. On-prem farms that still sit below the August 2026 fixed builds are the pager case, especially internet-facing SharePoint hosts where low-priv accounts are common.&lt;/p&gt;

&lt;p&gt;Affected product lines and fixed builds from MSRC affectedProduct (release 2026-Aug):&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;SharePoint Server Subscription Edition&lt;/strong&gt;: KB5002893 → build &lt;code&gt;16.0.19725.20522&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;SharePoint Server 2019&lt;/strong&gt;: KB5002894 → build &lt;code&gt;16.0.10417.20198&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;SharePoint Enterprise Server 2016&lt;/strong&gt; (same KB also covers SharePoint Server 2016): KB5002905 → build &lt;code&gt;16.0.5565.1001&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Reboot guidance on those rows is Maybe. If multiple updates apply for the software on the box, MSRC FAQ says install all of them; order does not matter.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;SharePoint Online / Microsoft 365 cloud SharePoint&lt;/strong&gt;. MSRC lists only the three on-prem server SKUs above. This KEV row is not a SharePoint Online patch ticket.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Farms already on or above the August 2026 fixed builds&lt;/strong&gt; for your SKU (SE &lt;code&gt;16.0.19725.20522&lt;/code&gt;, 2019 &lt;code&gt;16.0.10417.20198&lt;/code&gt;, 2016 &lt;code&gt;16.0.5565.1001&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Unauthenticated internet worms&lt;/strong&gt; as the PR:L model. The CVSS privileges-required is Low, not None. You still need an authorized (low-priv) attacker who can reach the farm.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Other Microsoft products outside those SharePoint Server trains&lt;/strong&gt; named on this CVE. Patch them on their own advisories; do not treat 65660 as coverage for unrelated MSRC rows.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;

&lt;p&gt;On a SharePoint server, print the installed product build, then compare it to the fixed build for your SKU:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="c"&gt;# SharePoint Management Shell / elevated PowerShell&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Get-SPFarm&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;BuildVersion&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="c"&gt;# or, from the binaries folder for your train:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Get-Item&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\ISAPI\Microsoft.SharePoint.dll"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;VersionInfo&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;FileVersion&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You want at least &lt;code&gt;16.0.19725.20522&lt;/code&gt; (Subscription Edition), &lt;code&gt;16.0.10417.20198&lt;/code&gt; (2019), or &lt;code&gt;16.0.5565.1001&lt;/code&gt; (2016 / Enterprise 2016). Anything lower on that train is still open for this KEV row.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Install the August 2026 security update for your SharePoint Server SKU, then confirm the build:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt; &lt;strong&gt;Subscription Edition&lt;/strong&gt;: &lt;a href="https://support.microsoft.com/help/5002893" rel="noopener noreferrer"&gt;KB5002893&lt;/a&gt; → build &lt;code&gt;16.0.19725.20522&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;SharePoint Server 2019&lt;/strong&gt;: &lt;a href="https://support.microsoft.com/help/5002894" rel="noopener noreferrer"&gt;KB5002894&lt;/a&gt; → build &lt;code&gt;16.0.10417.20198&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;SharePoint Server 2016 / Enterprise Server 2016&lt;/strong&gt;: &lt;a href="https://support.microsoft.com/help/5002905" rel="noopener noreferrer"&gt;KB5002905&lt;/a&gt; → build &lt;code&gt;16.0.5565.1001&lt;/code&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Prefer the path your farm already uses (WSUS / ConfigMgr / manual KB). After the update, re-run the build check above. Federal agencies under BOD 26-04 also owe forensic triage before or with the patch window; the KEV due date is 2026-09-28.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not unauthenticated remote code execution. Privileges required are Low (an authorized attacker), not None. It is also not a first-day disclosure story: the MSRC update shipped 2026-08-11. Treat it as authenticated code injection RCE that CISA now says is known-exploited, on widely deployed on-prem SharePoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660" rel="noopener noreferrer"&gt;MSRC CVE-2026-65660&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://support.microsoft.com/help/5002893" rel="noopener noreferrer"&gt;KB5002893 (Subscription Edition)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://support.microsoft.com/help/5002894" rel="noopener noreferrer"&gt;KB5002894 (SharePoint Server 2019)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://support.microsoft.com/help/5002905" rel="noopener noreferrer"&gt;KB5002905 (SharePoint Server 2016)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; (CVE-2026-65660, dateAdded 2026-09-25, dueDate 2026-09-28, BOD 26-04)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65660" rel="noopener noreferrer"&gt;NVD CVE-2026-65660&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>sharepoint</category>
      <category>microsoft</category>
      <category>rce</category>
    </item>
    <item>
      <title>Magento incorrect authorization hits CISA KEV</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Fri, 25 Sep 2026 02:30:38 +0000</pubDate>
      <link>https://dev.to/hol/magento-incorrect-authorization-hits-cisa-kev-1ha8</link>
      <guid>https://dev.to/hol/magento-incorrect-authorization-hits-cisa-kev-1ha8</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-71362-adobe-commerce-magento-authz-kev" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog today (2026-09-24).&lt;/strong&gt; Adobe published APSB26-92 on 2026-08-11 for Adobe Commerce and Magento Open Source. The Critical row is Incorrect Authorization (CWE-863): privilege escalation with no login and no user click, CVSS 3.1 base 9.1 (&lt;code&gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N&lt;/code&gt;). Federal KEV due date is 2026-09-27. Forensic triage is marked Yes under BOD 26-04. Adobe's August bulletin said it was not aware of exploits in the wild for the issues in that update; CISA's KEV listing is the later exploitation signal. Do not treat Adobe's August wording as a clean bill of health after today.&lt;/p&gt;

&lt;p&gt;This is the operator write-up from APSB26-92, Adobe's Experience League KB for that bulletin, CISA KEV catalogVersion 2026.09.24, and NVD. The HOL Guard evidence pack for this CVE, when it lands, is the &lt;a href="https://hol.org/guard/security/cves/CVE-2026-71362?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-71362-adobe-commerce-magento-authz-kev" rel="noopener noreferrer"&gt;linked source record&lt;/a&gt;; this page is the fix-first summary. Sibling CVEs in the same August bulletin (XSS and other authz rows) share the upgrade train; this article tracks the KEV row only.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;Adobe rates CVE-2026-71362 Critical. Impact is privilege escalation: an attacker can gain elevated access to sensitive resources without authentication and without user interaction. Reporter credit on the bulletin: 0x0.eth (0x0doteth). Magento storefronts and Adobe Commerce backends that still sit on July 2026 security trains (or earlier) are the pager case, especially internet-facing commerce hosts.&lt;/p&gt;

&lt;p&gt;Affected product lines from APSB26-92:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Adobe Commerce&lt;/strong&gt;: &lt;code&gt;2.4.9-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.8-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.7-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.6-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.5-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.4-2026-jul&lt;/code&gt; and earlier&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Adobe Commerce B2B&lt;/strong&gt;: &lt;code&gt;1.5.3-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;1.5.2-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;1.4.2-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;1.3.4-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;1.3.3-2026-jul&lt;/code&gt; and earlier&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Magento Open Source&lt;/strong&gt;: &lt;code&gt;2.4.9-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.8-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.7-2026-jul&lt;/code&gt; and earlier, &lt;code&gt;2.4.6-2026-jul&lt;/code&gt; and earlier&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Fixed trains named in the bulletin are the matching August 2026 builds (&lt;code&gt;*-2026-aug&lt;/code&gt;), including Adobe Commerce through &lt;code&gt;2.4.4-2026-aug&lt;/code&gt;, Magento Open Source through &lt;code&gt;2.4.6-2026-aug&lt;/code&gt;, and matching B2B &lt;code&gt;*-2026-aug&lt;/code&gt; builds. Adobe's KB for APSB26-92 also ships Isolated security patch ZIPs for merchants who need a lighter path than a full Composer cycle; Cloud merchants may already receive the same fixes via Magento Cloud Patches. Confirm against the live bulletin and KB for your edition before you close the ticket.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Hosts already on the August 2026 security trains&lt;/strong&gt; listed in APSB26-92 (&lt;code&gt;*-2026-aug&lt;/code&gt; for your Commerce / Magento / B2B line), or that already show CVE-2026-71362 as protected in Adobe's Commerce Version Tool after the August Isolated patch.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Magento Open Source 2.4.5 / 2.4.4 lines&lt;/strong&gt; for this specific bulletin row. APSB26-92 lists those trains under Adobe Commerce only, not under Magento Open Source.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Other Adobe products outside Commerce / Magento Open Source / Commerce B2B&lt;/strong&gt; named in APSB26-92. This KEV row is not a free pass to ignore unrelated Adobe bulletins, but it is not their vulnerability either.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Prior Magento stories already on this blog&lt;/strong&gt; (StyleSmuggler template RCE CVE-2026-75650, APSB26-138 authz CVE-2026-77774). Different CVEs, different upgrade trains. Do not treat those posts as coverage for 71362.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;

&lt;p&gt;From the Commerce / Magento project root, print the installed product version, then ask Adobe's patch-status tool whether CVE-2026-71362 is protected (CVT ships with the July 2026 Isolated patch train per Adobe's KB):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;php bin/magento &lt;span class="nt"&gt;--version&lt;/span&gt;
php vendor/bin/patch-status &lt;span class="nt"&gt;--version&lt;/span&gt;
php vendor/bin/patch-status
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Read &lt;code&gt;applied_patches&lt;/code&gt;, &lt;code&gt;missing_patches&lt;/code&gt;, and the per-CVE &lt;code&gt;vulnerability_status&lt;/code&gt; for CVE-2026-71362 (&lt;code&gt;PROTECTED&lt;/code&gt; / &lt;code&gt;VULNERABLE&lt;/code&gt; / &lt;code&gt;UNKNOWN&lt;/code&gt;). If &lt;code&gt;patch-status&lt;/code&gt; is missing, you are not on a train that already pulled CVT; apply the July Isolated patch first per Adobe's KB, then re-run. Cloud-only alternative from the same KB: Quality Patches Tool status for the August Isolated patch id that matches your line.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Move every affected Commerce / Magento / B2B install onto the August 2026 security train for your line (examples from APSB26-92: &lt;code&gt;2.4.9-2026-aug&lt;/code&gt; … &lt;code&gt;2.4.4-2026-aug&lt;/code&gt; for Adobe Commerce; Magento Open Source through &lt;code&gt;2.4.6-2026-aug&lt;/code&gt;; matching B2B &lt;code&gt;*-2026-aug&lt;/code&gt;). Prefer the path your ops already use:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt; &lt;strong&gt;Composer / full security update&lt;/strong&gt; when Adobe publishes packages for your line, or you are already on a Composer-based monthly security workflow.&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Isolated security patch ZIP&lt;/strong&gt; from Adobe's APSB26-92 KB when your line is classified as Isolated-only for August 2026 (Adobe notes Composer packages were not published alongside several of those trains). Apply July's Isolated patches first; August builds on July and must be applied in order. Example zip names from the KB include &lt;code&gt;2-4-9-aug-2026.zip&lt;/code&gt;, &lt;code&gt;2-4-8-p5-aug-2026.zip&lt;/code&gt;, &lt;code&gt;2-4-7-p10-aug-2026.zip&lt;/code&gt;, &lt;code&gt;2-4-6-p15-aug-2026.zip&lt;/code&gt;, and composer-key-gated zips for older Commerce lines.&lt;/li&gt;
&lt;li&gt; &lt;strong&gt;Adobe Commerce on Cloud&lt;/strong&gt;: pull the latest Magento Cloud Patches / cloud-patches update that includes APSB26-92. Adobe warns that stacking the Isolated ZIP on top of an already-patched cloud-patches install can fail.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;After the update, re-run &lt;code&gt;php vendor/bin/patch-status&lt;/code&gt; and confirm CVE-2026-71362 is &lt;code&gt;PROTECTED&lt;/code&gt;. Federal agencies under BOD 26-04 also owe forensic triage before or with the patch window; the KEV due date is 2026-09-27.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not a remote code execution bug in the Adobe table for CVE-2026-71362, and it is not a first-day disclosure story: APSB26-92 shipped 2026-08-11. Availability impact is listed as None in the CVSS vector. Treat it as unauthenticated privilege escalation that CISA now says is known-exploited, on a widely deployed commerce stack.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://helpx.adobe.com/security/products/magento/apsb26-92.html" rel="noopener noreferrer"&gt;Adobe APSB26-92&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380" rel="noopener noreferrer"&gt;Adobe Experience League: Security update APSB26-92 (Isolated patches / CVT)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;CISA Known Exploited Vulnerabilities catalog&lt;/a&gt; (CVE-2026-71362, dateAdded 2026-09-24, dueDate 2026-09-27, BOD 26-04)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71362" rel="noopener noreferrer"&gt;NVD CVE-2026-71362&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/advisories/GHSA-f58v-hxr9-8947" rel="noopener noreferrer"&gt;GitHub Advisory GHSA-f58v-hxr9-8947&lt;/a&gt; (unreviewed mirror of the CVE record)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>adobecommerce</category>
      <category>magento</category>
      <category>authorization</category>
    </item>
    <item>
      <title>F5 BIG-IP APM OAuth RCE hits CISA KEV</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Tue, 22 Sep 2026 19:58:31 +0000</pubDate>
      <link>https://dev.to/hol/f5-big-ip-apm-oauth-rce-hits-cisa-kev-57gd</link>
      <guid>https://dev.to/hol/f5-big-ip-apm-oauth-rce-hits-cisa-kev-57gd</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog today (2026-09-22).&lt;/strong&gt; F5 published the same-day advisory for BIG-IP Access Policy Manager: when an APM access policy and an OAuth profile share a virtual server, crafted traffic can trigger a heap buffer overflow and remote code execution with no login. Appliance mode is in scope. This is a data-plane bug; the control plane is not the exposure. Federal KEV due date is 2026-09-25. Forensic triage is marked Yes. CISA's notes say apply F5's temporary iRule for triage, then install the vendor hotfix.&lt;/p&gt;

&lt;p&gt;This is the operator write-up from the F5 CVE record (K000162605), CISA KEV catalogVersion 2026.09.22, and NVD's received listing. The HOL Guard evidence pack for this CVE, when it lands, is the linked source record; this page is the fix-first summary.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;F5 rates the issue Critical. CVSS 3.1 base score is 9.8 (&lt;code&gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&lt;/code&gt;). CVSS 4.0 base from the CNA is 9.3. Weakness: heap-based buffer overflow (CWE-122). The precondition is configuration, not "every BIG-IP on the internet": the virtual server must have both an APM access policy and an OAuth profile attached. Under that setup, specific malicious traffic to the virtual server can reach RCE without authentication.&lt;/p&gt;

&lt;p&gt;Affected trains from the F5 CNA record:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;21.1.0&lt;/strong&gt; until &lt;code&gt;Hotfix-BIGIP-21.1.0.2.0.30.22-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;17.5.0&lt;/strong&gt; (through the 17.5.1 line in secondary reporting) until &lt;code&gt;Hotfix-BIGIP-17.5.1.9.0.160.12-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;17.1.0&lt;/strong&gt; (through 17.1.3 in secondary reporting) until &lt;code&gt;Hotfix-BIGIP-17.1.3.5.0.41.14-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Software past End of Technical Support is not evaluated. Treat internet-facing APM+OAuth virtual servers as the pager case. BOD 26-04 triage applies because this is same-day KEV.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Virtual servers without both an APM access policy and an OAuth profile.&lt;/strong&gt; The CNA text gates the bug on that pair. LTM-only VIPs, or APM without OAuth (or OAuth without APM) on the same virtual server, are outside this specific failure mode.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Control-plane management paths as the attack surface.&lt;/strong&gt; F5 states this is a data-plane issue with no control-plane exposure. That does not mean the box is safe; it means the exploit rides traffic to the VIP, not the config UI by itself.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Other BIG-IP modules and NGINX products called out as unaffected&lt;/strong&gt; in secondary advisory summaries that track K000162605. Confirm against the live F5 article for your licensed modules before you close the ticket.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Boxes already on the listed engineering hotfixes&lt;/strong&gt; for your train. The fix is the ENG hotfix named above, not a marketing point release alone.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;

&lt;p&gt;On each BIG-IP that terminates APM, run:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;tmsh show sys version
tmsh list ltm virtual one-line | &lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-E&lt;/span&gt; &lt;span class="s1"&gt;'profiles|access-policy|oauth'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Confirm the software build, then inventory every virtual server that shows both an access policy and an OAuth profile. Any VIP that has both is in the KEV blast radius until the matching ENG hotfix is installed (or until you remove one of those two bindings as a temporary reduction of exposure).&lt;/p&gt;

&lt;p&gt;If you already use a config-management export, grep the UCS/SCF for &lt;code&gt;oauth&lt;/code&gt; profiles attached beside APM access policies on the same virtual server object. That is the same check without interactive tmsh.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Install the F5 engineering hotfix for your train, then re-check version:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;21.1.0:&lt;/strong&gt; &lt;code&gt;Hotfix-BIGIP-21.1.0.2.0.30.22-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;17.5.x:&lt;/strong&gt; &lt;code&gt;Hotfix-BIGIP-17.5.1.9.0.160.12-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;17.1.x:&lt;/strong&gt; &lt;code&gt;Hotfix-BIGIP-17.1.3.5.0.41.14-ENG&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pull the package from MyF5 per K000162605, stage it in a change window, and verify &lt;code&gt;tmsh show sys version&lt;/code&gt; shows the hotfix build after reboot. If you cannot patch immediately, contact F5 Support for the vendor-provided iRule mitigation CISA references for forensic triage, restrict or disable the exposed APM+OAuth virtual servers where business allows, and treat the box as potentially compromised before you trust a late patch. KEV due date: 2026-09-25.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not a worm that hits every BIG-IP regardless of config. It is unauthenticated RCE, but only after APM access policy and OAuth share a virtual server. It is also not a control-plane auth bypass; the overflow is on the data plane VIP path.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  F5 advisory K000162605: &lt;a href="https://my.f5.com/manage/s/article/K000162605" rel="noopener noreferrer"&gt;https://my.f5.com/manage/s/article/K000162605&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  CVE record: &lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-94127" rel="noopener noreferrer"&gt;https://www.cve.org/CVERecord?id=CVE-2026-94127&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  NVD: &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-94127" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-94127&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  CISA KEV catalog (catalogVersion 2026.09.22): &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" rel="noopener noreferrer"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  HOL Guard evidence pack: &lt;a href="https://hol.org/guard/security/cves/CVE-2026-94127?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-94127-f5-big-ip-apm-oauth-rce-kev" rel="noopener noreferrer"&gt;https://hol.org/guard/security/cves/CVE-2026-94127&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>f5</category>
      <category>bigip</category>
      <category>apm</category>
    </item>
    <item>
      <title>BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Tue, 22 Sep 2026 17:43:23 +0000</pubDate>
      <link>https://dev.to/hol/breaking-nextjs-nextog-imageresponse-rce-on-nodejs-ghsa-vcvr-r3jv-pc5j-4hmc</link>
      <guid>https://dev.to/hol/breaking-nextjs-nextog-imageresponse-rce-on-nodejs-ghsa-vcvr-r3jv-pc5j-4hmc</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/ghsa-vcvr-r3jv-pc5j-nextjs-og-imageresponse-rce" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)
&lt;/h1&gt;

&lt;p&gt;Vercel published an out-of-band Next.js security update on 2026-09-22. The Critical path is remote code execution in the Node.js &lt;code&gt;ImageResponse&lt;/code&gt; implementation from &lt;code&gt;next/og&lt;/code&gt; (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j, CVSS 9.5). It comes from improper SVG escaping in upstream Satori (GHSA-wx4j-mvgx-mqwp), which Next.js pulls in for OG image generation. Patched Next.js is &lt;code&gt;16.3.6&lt;/code&gt;. Next.js 15.x is not affected by the RCE; &lt;code&gt;15.5.26&lt;/code&gt; is hardening only. GitHub now lists &lt;strong&gt;CVE-2026-94545&lt;/strong&gt; on GHSA-vcvr-r3jv-pc5j (NVD and cve.org still empty at patch time). This is the operator write-up from the Next.js blog and the GitHub advisories.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;p&gt;Skip the pager if any of these hold:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  You already run &lt;code&gt;next@16.3.6&lt;/code&gt; or newer on the 16.x train.&lt;/li&gt;
&lt;li&gt;  The app is on Next.js 15.x for the RCE itself. The September 22 cut still ships &lt;code&gt;15.5.26&lt;/code&gt; as related hardening, but the vendor states 15.x is not affected by this remote code execution issue.&lt;/li&gt;
&lt;li&gt;  You use only the Edge &lt;code&gt;ImageResponse&lt;/code&gt; implementation. Edge is not affected.&lt;/li&gt;
&lt;li&gt;  Your Node.js &lt;code&gt;ImageResponse&lt;/code&gt; handlers never pass attacker-controlled values into SVG content, attributes, or styles during image generation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a public OG route takes a query param, header, or other request field and drops it into JSX/SVG that &lt;code&gt;ImageResponse&lt;/code&gt; renders on Node, treat yourself as in scope until you patch.&lt;/p&gt;

&lt;h2&gt;
  
  
  What broke
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Next.js Node.js &lt;code&gt;ImageResponse&lt;/code&gt; RCE (CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j).&lt;/strong&gt; Affected &lt;code&gt;next&lt;/code&gt; versions are &lt;code&gt;&amp;gt;= 16.2.0&lt;/code&gt; and &lt;code&gt;&amp;lt; 16.3.6&lt;/code&gt;. The Node.js path from &lt;code&gt;next/og&lt;/code&gt; is vulnerable when attacker-controlled values reach SVG content, attributes, or styles. The advisory example wires a &lt;code&gt;searchParams&lt;/code&gt; value into an SVG &lt;code&gt;&amp;lt;title&amp;gt;&lt;/code&gt; inside &lt;code&gt;ImageResponse&lt;/code&gt;. Under those conditions, improper escaping in Satori-generated SVG can lead to remote code execution through other upstream dependencies. The Next.js fix upgrades those dependencies. Severity on the GHSA is Critical 9.5 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Credit: KarimPwnz.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Upstream Satori improper SVG escaping (GHSA-wx4j-mvgx-mqwp).&lt;/strong&gt; Satori versions &lt;code&gt;&amp;gt;= 0.0.27&lt;/code&gt; and &lt;code&gt;&amp;lt; 0.33.5&lt;/code&gt; do not properly escape certain values before including them in generated SVG. Crafted values can be interpreted as SVG markup. Impact depends on how the SVG is consumed. Patched Satori is &lt;code&gt;0.33.5&lt;/code&gt;. Severity is Moderate 5.3. For Next.js apps, do not chase a standalone Satori bump as the product fix; install the patched Next.js release that vendors the upgrade.&lt;/p&gt;

&lt;p&gt;Confirmed on the npm registry today: &lt;code&gt;next@16.3.6&lt;/code&gt; and &lt;code&gt;next@15.5.26&lt;/code&gt; both resolve. The Next.js September 22, 2026 security update blog is live (no longer Upcoming). No matching Vercel changelog entry was present at publish time; use the Next.js blog and the two GHSAs as primary records.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not the August 2026 Image Optimization AVIF / libheif RCE (GHSA-2xp9-vwfh-vxw4). It is not CVE-2026-75604, the Windows path-traversal RCE that needed both routers without Cache Components. It is not automatic RCE on every &lt;code&gt;next/og&lt;/code&gt; use: Edge &lt;code&gt;ImageResponse&lt;/code&gt; is out, and Node handlers that never feed attacker-controlled values into SVG content, attributes, or styles are out. CVE ID &lt;strong&gt;CVE-2026-94545&lt;/strong&gt; is now on the GHSA page; NVD and the CVE.org record may still lag. We are not inventing the ID. We are not claiming CISA KEV listing or in-the-wild exploitation; that status is unknown from the primary sources.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check
&lt;/h2&gt;

&lt;p&gt;Confirm the &lt;code&gt;next&lt;/code&gt; package the running process actually loaded:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx next &lt;span class="nt"&gt;--version&lt;/span&gt;
&lt;span class="c"&gt;# or&lt;/span&gt;
npm &lt;span class="nb"&gt;ls &lt;/span&gt;next
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;On the 16.x train, anything &lt;code&gt;&amp;gt;= 16.2.0&lt;/code&gt; and below &lt;code&gt;16.3.6&lt;/code&gt; is in the RCE window. Then inventory Node.js OG routes that take request input into SVG:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# look for Node ImageResponse from next/og (not Edge-only handlers)&lt;/span&gt;
rg &lt;span class="nt"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;"from ['&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s2"&gt;]next/og['&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s2"&gt;]|ImageResponse"&lt;/span&gt; app pages src &lt;span class="nt"&gt;--glob&lt;/span&gt; &lt;span class="s1"&gt;'*.{js,jsx,ts,tsx}'&lt;/span&gt;
&lt;span class="c"&gt;# then check whether searchParams, headers, cookies, or body fields land in SVG props/children/styles&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If that path exists and you are still below &lt;code&gt;16.3.6&lt;/code&gt;, patch before you argue about whether the values are "really" attacker-controlled.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install &lt;/span&gt;next@16.3.6   &lt;span class="c"&gt;# 16.x Active LTS (RCE fix)&lt;/span&gt;
npm &lt;span class="nb"&gt;install &lt;/span&gt;next@15.5.26  &lt;span class="c"&gt;# 15.x Maintenance LTS (hardening only; 15.x not affected by the RCE)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you cannot upgrade immediately, the GHSA workaround is: do not pass attacker-controlled values into SVG content, attributes, or styles rendered by the Node.js &lt;code&gt;ImageResponse&lt;/code&gt; implementation from &lt;code&gt;next/og&lt;/code&gt;. That is a temporary constraint, not a substitute for &lt;code&gt;16.3.6&lt;/code&gt; on affected 16.x apps.&lt;/p&gt;

&lt;p&gt;HOL Guard does not have a source record for GHSA-vcvr-r3jv-pc5j yet (the Guard CVE evidence pack 404s today). Use the Next.js September 22, 2026 security update and the GitHub advisories as the primary records until Guard ingests it.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://nextjs.org/blog/nextjs-security-update-september-22-2026" rel="noopener noreferrer"&gt;Next.js security update: September 22, 2026&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j" rel="noopener noreferrer"&gt;GHSA-vcvr-r3jv-pc5j (Next.js next/og ImageResponse RCE)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp" rel="noopener noreferrer"&gt;GHSA-wx4j-mvgx-mqwp (Satori improper SVG escaping)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://hol.org/blog/cve-2026-75604-nextjs-unauth-rce-image-optimization-windows?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=ghsa-vcvr-r3jv-pc5j-nextjs-og-imageresponse-rce" rel="noopener noreferrer"&gt;Prior related HOL write-up: CVE-2026-75604 / August Image Optimization path (different bugs)&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ghsa</category>
      <category>cve</category>
      <category>nextjs</category>
      <category>rce</category>
    </item>
    <item>
      <title>Your Erlang TLS 1.3 client can trust a server with no certificate</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Tue, 22 Sep 2026 13:05:32 +0000</pubDate>
      <link>https://dev.to/hol/your-erlang-tls-13-client-can-trust-a-server-with-no-certificate-2kgc</link>
      <guid>https://dev.to/hol/your-erlang-tls-13-client-can-trust-a-server-with-no-certificate-2kgc</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-89422-erlang-otp-tls13-unsolicited-psk-auth-bypass" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;An Erlang/OTP TLS 1.3 client can finish &lt;code&gt;ssl:connect&lt;/code&gt; against a peer that never sent a certificate.&lt;/strong&gt; Erlang published &lt;strong&gt;CVE-2026-89422&lt;/strong&gt; today (CVSS 4.0 9.3 Critical, CWE-322). If the ServerHello carries a &lt;code&gt;pre_shared_key&lt;/code&gt; extension the client never offered, the default client marks the handshake as resumed, skips certificate path validation, hostname checks, &lt;code&gt;verify_fun&lt;/code&gt;, CRL, and OCSP, and still returns &lt;code&gt;{ok, Socket}&lt;/code&gt;. The peer needs no cert, no private key, and no prior session. After that handshake the attacker holds the traffic keys, so it can read credentials, tokens, and request bodies and forge every response.&lt;/p&gt;

&lt;p&gt;Ship the same OTP upgrade for the same-day siblings &lt;strong&gt;CVE-2026-68956&lt;/strong&gt; (SSH idle session-channel memory DoS, CVSS 4.0 7.1 High) and &lt;strong&gt;CVE-2026-65634&lt;/strong&gt; (ASN.1 OBJECT IDENTIFIER decode CPU DoS during TLS cert parsing, CVSS 4.0 8.2 High). Do not open a second article for that train. This is the operator write-up; the HOL Guard evidence packs for &lt;a href="https://hol.org/guard/security/cves/CVE-2026-89422?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89422-erlang-otp-tls13-unsolicited-psk-auth-bypass" rel="noopener noreferrer"&gt;CVE-2026-89422&lt;/a&gt;, &lt;a href="https://hol.org/guard/security/cves/CVE-2026-68956?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89422-erlang-otp-tls13-unsolicited-psk-auth-bypass" rel="noopener noreferrer"&gt;CVE-2026-68956&lt;/a&gt;, and &lt;a href="https://hol.org/guard/security/cves/CVE-2026-65634?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89422-erlang-otp-tls13-unsolicited-psk-auth-bypass" rel="noopener noreferrer"&gt;CVE-2026-65634&lt;/a&gt; are the source records.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;On &lt;strong&gt;CVE-2026-89422&lt;/strong&gt;, &lt;code&gt;tls_client_connection_1_3:handle_server_hello/2&lt;/code&gt; passes a received &lt;code&gt;pre_shared_key&lt;/code&gt; extension into &lt;code&gt;tls_gen_connection_1_3:handle_resumption/2&lt;/code&gt;, which sets &lt;code&gt;resumption = true&lt;/code&gt; on presence alone without checking that the client offered a PSK. Meanwhile &lt;code&gt;tls_handshake_1_3:get_pre_shared_key/4&lt;/code&gt; falls back to the all-zero "no PSK" value and keys the handshake with the ordinary non-PSK schedule, so the attacker's own ephemeral key is enough. The resumption flag then routes &lt;code&gt;maybe_resumption/1&lt;/code&gt; straight to &lt;code&gt;wait_finished&lt;/code&gt;, skipping the certificate-handling states.&lt;/p&gt;

&lt;p&gt;The default recommended client config is in scope: &lt;code&gt;{verify, verify_peer}&lt;/code&gt; with trusted cacerts, TLS 1.3 enabled and preferred, and default &lt;code&gt;session_tickets = disabled&lt;/code&gt;. The &lt;code&gt;session_tickets&lt;/code&gt; modes &lt;code&gt;manual&lt;/code&gt; and &lt;code&gt;auto&lt;/code&gt; are equally affected whenever the client has no ticket to offer, including every first connection to a host. Any consumer of &lt;code&gt;ssl:connect&lt;/code&gt; that negotiates TLS 1.3 is exposed, including &lt;code&gt;httpc&lt;/code&gt; over HTTPS, database and messaging client libraries, and TLS distribution clients.&lt;/p&gt;

&lt;p&gt;Application-visible clues on an affected connection: &lt;code&gt;ssl:peercert/1&lt;/code&gt; returns &lt;code&gt;{error, no_peercert}&lt;/code&gt; despite &lt;code&gt;verify_peer&lt;/code&gt;, and &lt;code&gt;ssl:connection_information/2&lt;/code&gt; reports &lt;code&gt;{session_resumption, true}&lt;/code&gt; for a client that never held a ticket.&lt;/p&gt;

&lt;p&gt;On &lt;strong&gt;CVE-2026-68956&lt;/strong&gt;, an authenticated SSH client can open many &lt;code&gt;session&lt;/code&gt; channels that never get a shell, exec, or subsystem handler. Those idle channel records still land in the ETS channel cache, but &lt;code&gt;max_channels&lt;/code&gt; only counts supervisor children, so the option does not bound the attack. One authenticated connection can grow memory until the emulator exits.&lt;/p&gt;

&lt;p&gt;On &lt;strong&gt;CVE-2026-65634&lt;/strong&gt;, the BER/PER/JER OBJECT IDENTIFIER decoders accumulate an unbounded base-128 subidentifier with quadratic work. A crafted OID (roughly 262 KB of continuation bytes in the advisory's example) can burn about 13 seconds of CPU on typical hardware. The decoder is generated into modules that parse X.509, including &lt;code&gt;OTP-PUB-KEY&lt;/code&gt; via &lt;code&gt;public_key:pkix_decode_cert/2&lt;/code&gt;, and it runs before signature or trust-chain verification. Default TLS clients (always parse the server cert) and mTLS servers (parse client certs) are exposed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  TLS &lt;strong&gt;clients restricted to TLS 1.2&lt;/strong&gt; via &lt;code&gt;{versions, ['tlsv1.2']}&lt;/code&gt; are not affected by CVE-2026-89422 (they never hit the TLS 1.3 client path).&lt;/li&gt;
&lt;li&gt;  OTP builds already on &lt;strong&gt;29.1.1&lt;/strong&gt;, &lt;strong&gt;28.5.0.7&lt;/strong&gt;, or &lt;strong&gt;27.3.4.18&lt;/strong&gt; (and later on those trains) are patched for this cluster.&lt;/li&gt;
&lt;li&gt;  CVE-2026-68956 needs a successfully &lt;strong&gt;authenticated&lt;/strong&gt; SSH session; it is not an unauthenticated internet worm. Network-restricted SSH daemons shrink exposure but do not replace the upgrade.&lt;/li&gt;
&lt;li&gt;  CVE-2026-65634 is a CPU denial of service during cert/OID parse, not a certificate forgery or auth bypass by itself.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade Erlang/OTP to one of:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;OTP 29.1.1
OTP 28.5.0.7
OTP 27.3.4.18
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Matching application versions called out by ERLEF:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  ssl: 11.7.7 / 11.6.0.6 / 11.2.12.13&lt;/li&gt;
&lt;li&gt;  ssh: 6.0.6 / 5.5.2.6 / 5.2.11.13&lt;/li&gt;
&lt;li&gt;  asn1: 5.5.2 / 5.4.3.1 / 5.3.4.3&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Rebuild and redeploy every BEAM release, container image, and host package that embeds OTP (Elixir releases, RabbitMQ nodes, CouchDB, ejabberd, custom &lt;code&gt;ssl:connect&lt;/code&gt; clients, and SSH daemons). There is &lt;strong&gt;no&lt;/strong&gt; configuration that both keeps TLS 1.3 and mitigates CVE-2026-89422. The only temporary workaround is forcing TLS 1.2 on affected clients until you can patch.&lt;/p&gt;

&lt;p&gt;For SSH while you roll: restrict who can authenticate, set a finite &lt;code&gt;max_sessions&lt;/code&gt;, and rate-limit connections. Do not rely on &lt;code&gt;max_channels&lt;/code&gt; for the idle-session bug.&lt;/p&gt;

&lt;h2&gt;
  
  
  One concrete check
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight erlang"&gt;&lt;code&gt;&lt;span class="n"&gt;erl&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;noshell&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;eval&lt;/span&gt; &lt;span class="n"&gt;'io:format("~s~n", [erlang:system_info(otp_release)]), halt().'&lt;/span&gt;
&lt;span class="err"&gt;#&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;for&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;full&lt;/span&gt; &lt;span class="n"&gt;patch&lt;/span&gt; &lt;span class="n"&gt;level&lt;/span&gt; &lt;span class="n"&gt;on&lt;/span&gt; &lt;span class="n"&gt;modern&lt;/span&gt; &lt;span class="nv"&gt;OTP&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;span class="n"&gt;erl&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;noshell&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;eval&lt;/span&gt; &lt;span class="n"&gt;'{ok, V} = file:read_file(filename:join([code:root_dir(), "releases", "RELEASES"])), io:format("~s~n",[V]), halt().'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Or check the package you actually ship:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;rabbitmqctl status | &lt;span class="nb"&gt;head&lt;/span&gt;
&lt;span class="c"&gt;# Elixir releases often embed OTP; inspect the release's erts / OTP version&lt;/span&gt;
&lt;span class="nb"&gt;cat &lt;/span&gt;_build/prod/rel/&lt;span class="k"&gt;*&lt;/span&gt;/releases/&lt;span class="k"&gt;*&lt;/span&gt;/OTP_VERSION 2&amp;gt;/dev/null &lt;span class="o"&gt;||&lt;/span&gt; &lt;span class="nb"&gt;true&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If you are below 27.3.4.18 / 28.5.0.7 / 29.1.1 on those trains, treat TLS 1.3 clients and ASN.1/TLS cert parse surfaces as exposed until the bump lands.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not remote code execution, not an unauthenticated worm across the open internet, and not a bug that only hits exotic PSK ticket configs. It is a TLS 1.3 client authentication bypass under default settings, plus two High DoS siblings fixed on the same OTP patch train.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://cna.erlef.org/cves/CVE-2026-89422.html" rel="noopener noreferrer"&gt;ERLEF CNA: CVE-2026-89422&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875" rel="noopener noreferrer"&gt;GHSA-rgxr-4g4w-j875&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://cna.erlef.org/cves/CVE-2026-68956.html" rel="noopener noreferrer"&gt;ERLEF CNA: CVE-2026-68956&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://cna.erlef.org/cves/CVE-2026-65634.html" rel="noopener noreferrer"&gt;ERLEF CNA: CVE-2026-65634&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/erlang/otp/releases/tag/OTP-29.1.1" rel="noopener noreferrer"&gt;OTP 29.1.1 release&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>erlang</category>
      <category>otp</category>
      <category>tls</category>
    </item>
    <item>
      <title>Temporal write access can run shell on your Worker Service host</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Mon, 21 Sep 2026 13:27:22 +0000</pubDate>
      <link>https://dev.to/hol/temporal-write-access-can-run-shell-on-your-worker-service-host-1767</link>
      <guid>https://dev.to/hol/temporal-write-access-can-run-shell-on-your-worker-service-host-1767</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-89139-temporal-worker-subprocess-rce-callback-admin" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Anyone with write access in a single Temporal namespace can make the Worker Service host run a shell command of their choosing.&lt;/strong&gt; Temporal published &lt;strong&gt;CVE-2026-89139&lt;/strong&gt; today (CVSS 4.0 8.7 High). The Worker Controller's built-in &lt;code&gt;subprocess&lt;/code&gt; compute provider takes the program and argv from the caller's worker-deployment request, not from operator config, and runs it immediately on the Worker Service machine. That process holds persistence credentials for every namespace and the cluster TLS material, so one namespace write reaches the whole cluster.&lt;/p&gt;

&lt;p&gt;Ship the same upgrade for the sibling admin-callback bug &lt;strong&gt;CVE-2026-87858&lt;/strong&gt; (CVSS 4.0 7.2 High): a caller-controlled &lt;code&gt;source&lt;/code&gt; header on a completion callback can retarget the History service at the internal frontend as system administrator. Do not open a second article for that train. This is the operator write-up; the HOL Guard evidence packs for &lt;a href="https://hol.org/guard/security/cves/CVE-2026-89139?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89139-temporal-worker-subprocess-rce-callback-admin" rel="noopener noreferrer"&gt;CVE-2026-89139&lt;/a&gt; and &lt;a href="https://hol.org/guard/security/cves/CVE-2026-87858?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89139-temporal-worker-subprocess-rce-callback-admin" rel="noopener noreferrer"&gt;CVE-2026-87858&lt;/a&gt; are the source records.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;On &lt;strong&gt;CVE-2026-89139&lt;/strong&gt;, Temporal Server 1.31.0 through before 1.31.3 ships a Worker Controller Instance module inside the Worker Service. That module registers a compute provider named &lt;code&gt;subprocess&lt;/code&gt;. An authenticated caller with only a write role in one namespace can set a worker deployment version whose scaling group uses that provider. The handler validates the spec, then invokes every provider with the invoke strategy right away. No scaling event, task arrival, or unusual request sequence is required. The official &lt;code&gt;temporal-server&lt;/code&gt; binaries and container images include the provider.&lt;/p&gt;

&lt;p&gt;The only gate that can keep &lt;code&gt;subprocess&lt;/code&gt; unreachable is the per-namespace dynamic config &lt;code&gt;workercontroller.compute_providers.enabled&lt;/code&gt;. Its default is an unset list, and the allowlist check is skipped when the value is unset, so every registered provider is permitted. The separate &lt;code&gt;workercontroller.enabled&lt;/code&gt; flag defaults to false and does &lt;em&gt;not&lt;/em&gt; gate this path. Temporal confirmed an affected release with that setting never present anywhere in dynamic config is still exposed.&lt;/p&gt;

&lt;p&gt;On &lt;strong&gt;CVE-2026-87858&lt;/strong&gt;, History decided whether a Workflow completion callback was "internal" by reading a caller-supplied HTTP header named &lt;code&gt;source&lt;/code&gt;. A namespace writer who can attach a callback whose host matches &lt;code&gt;component.callbacks.allowedAddresses&lt;/code&gt;, and who can put a non-empty &lt;code&gt;source&lt;/code&gt; header on it (releases 1.30.0+), causes History to rewrite only scheme and host and send the caller's path, query, and body to the local frontend client. Where an internal frontend is deployed with its HTTP API enabled, that client authorizes every request as system administrator. Confirmed effects include terminating Workflows in other namespaces, registering namespaces, changing another namespace's config, and deleting another namespace and its Workflows. The same routing exists in both HSM and CHASM callback delivery. Releases 1.25.0 through 1.29.7 need the header to exactly match a configured cluster ID (harder). Upstream patches: &lt;a href="https://github.com/temporalio/temporal/pull/12021" rel="noopener noreferrer"&gt;PR 12021&lt;/a&gt; (auto-scaled-workers bump for the subprocess fix), &lt;a href="https://github.com/temporalio/temporal-auto-scaled-workers/pull/129" rel="noopener noreferrer"&gt;auto-scaled-workers PR 129&lt;/a&gt;, and &lt;a href="https://github.com/temporalio/temporal/pull/11965" rel="noopener noreferrer"&gt;PR 11965&lt;/a&gt; (make Nexus callback &lt;code&gt;source&lt;/code&gt; header inspection opt-in via &lt;code&gt;callback.inspectSourceHeader&lt;/code&gt;, default false).&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;p&gt;You are not in the CVE-2026-89139 blast radius if your Temporal Server is older than 1.31.0, or you are already on 1.31.3 / 1.32.0+, or the Worker Service is not running (non-default topologies only), or every namespace's &lt;code&gt;workercontroller.compute_providers.enabled&lt;/code&gt; is set to an explicit list that omits &lt;code&gt;subprocess&lt;/code&gt;. Deployments with no authorizer already grant every caller every namespace, so they have no namespace boundary for this bug to cross. For CVE-2026-87858, stock static topology without an internal frontend HTTP port, or an empty &lt;code&gt;component.callbacks.allowedAddresses&lt;/code&gt; (the default denies all external callback URLs), keeps the admin retarget closed. Temporal Cloud is a separate product; this write-up is about self-hosted Temporal Server.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;Neither CVE is unauthenticated internet RCE. Both need an authenticated Temporal principal with namespace write. CVE-2026-89139 is host command execution on the Worker Service under the server process account. CVE-2026-87858 is admin-equivalent state changes through the internal frontend, not a free remote shell by itself. Neither is listed on CISA KEV as of this writing.&lt;/p&gt;

&lt;h2&gt;
  
  
  One operator check
&lt;/h2&gt;

&lt;p&gt;On every self-hosted cluster, run the server binary or image tag check first:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;temporal-server &lt;span class="nt"&gt;--version&lt;/span&gt;
&lt;span class="c"&gt;# or&lt;/span&gt;
docker inspect &lt;span class="nt"&gt;--format&lt;/span&gt; &lt;span class="s1"&gt;'{{.Config.Image}}'&lt;/span&gt; temporal-frontend
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Treat 1.31.0, 1.31.1, and 1.31.2 as CVE-2026-89139-exposed until you are on &lt;strong&gt;1.31.3&lt;/strong&gt; or &lt;strong&gt;1.32.0&lt;/strong&gt;. For the callback sibling, treat 1.30.0 through before 1.30.7 and 1.31.0 through before 1.31.3 the same way; fixed trains are &lt;strong&gt;1.30.7&lt;/strong&gt;, &lt;strong&gt;1.31.3&lt;/strong&gt;, and &lt;strong&gt;1.32.0&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Then confirm the dangerous defaults are not still live while you schedule the upgrade:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;# dynamic config (per namespace). Unset = every compute provider allowed, including subprocess.
# Prefer an explicit allowlist that omits subprocess until you patch.
# workercontroller.compute_providers.enabled

callback allowlist empty by default (deny). Non-empty + internal-frontend httpPort &amp;gt; 0 = 87858 exposure window.
component.callbacks.allowedAddresses
services.internal-frontend.rpc.httpPort
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;To look for a subprocess config already attached, call &lt;code&gt;DescribeWorkerDeploymentVersion&lt;/code&gt; for each worker deployment version in each namespace and check whether any scaling group's compute provider type is &lt;code&gt;subprocess&lt;/code&gt;. For callbacks already attached, &lt;code&gt;DescribeWorkflowExecution&lt;/code&gt; returns registered completion callbacks. Note the frontend HTTP API logs method and URL at debug only, so missing log lines are not proof the admin path was unused.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;Upgrade Temporal Server to &lt;strong&gt;1.31.3&lt;/strong&gt; (or &lt;strong&gt;1.30.7&lt;/strong&gt; on the 1.30 train, or &lt;strong&gt;1.32.0&lt;/strong&gt;+):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Helm example. Pin the chart/app version that ships temporal-server 1.31.3 or 1.32.0.&lt;/span&gt;
helm upgrade temporal temporalio/temporal &lt;span class="nt"&gt;--version&lt;/span&gt; &amp;lt;chart-with-1.31.3-or-1.32.0&amp;gt;

Container
Use the official image tags that embed temporal-server 1.31.3 / 1.30.7 / 1.32.0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Release notes: &lt;a href="https://github.com/temporalio/temporal/releases/tag/v1.30.7" rel="noopener noreferrer"&gt;v1.30.7&lt;/a&gt;, &lt;a href="https://github.com/temporalio/temporal/releases/tag/v1.31.3" rel="noopener noreferrer"&gt;v1.31.3&lt;/a&gt;, &lt;a href="https://github.com/temporalio/temporal/releases/tag/v1.32.0" rel="noopener noreferrer"&gt;v1.32.0&lt;/a&gt;. After upgrade, re-check &lt;code&gt;temporal-server --version&lt;/code&gt;, confirm no worker deployment version still advertises provider type &lt;code&gt;subprocess&lt;/code&gt; unless you intentionally allow it post-patch, and leave &lt;code&gt;callback.inspectSourceHeader&lt;/code&gt; at its patched default (false) unless you are in a documented mixed-version escape hatch that still needs legacy HTTP worker callbacks.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-89139" rel="noopener noreferrer"&gt;NVD CVE-2026-89139&lt;/a&gt; (CVSS 4.0 8.7 High)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-87858" rel="noopener noreferrer"&gt;NVD CVE-2026-87858&lt;/a&gt; (CVSS 4.0 7.2 High)&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/temporalio/temporal/pull/12021" rel="noopener noreferrer"&gt;temporal PR 12021&lt;/a&gt; / &lt;a href="https://github.com/temporalio/temporal-auto-scaled-workers/pull/129" rel="noopener noreferrer"&gt;auto-scaled-workers PR 129&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/temporalio/temporal/pull/11965" rel="noopener noreferrer"&gt;temporal PR 11965&lt;/a&gt; (callback source header opt-in)&lt;/li&gt;
&lt;li&gt;  HOL Guard packs: &lt;a href="https://hol.org/guard/security/cves/CVE-2026-89139?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89139-temporal-worker-subprocess-rce-callback-admin" rel="noopener noreferrer"&gt;CVE-2026-89139&lt;/a&gt;, &lt;a href="https://hol.org/guard/security/cves/CVE-2026-87858?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-89139-temporal-worker-subprocess-rce-callback-admin" rel="noopener noreferrer"&gt;CVE-2026-87858&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>temporal</category>
      <category>rce</category>
      <category>authz</category>
    </item>
    <item>
      <title>BREAKING: OpenShift console Devfile API lets anyone SSRF your cluster</title>
      <dc:creator>Michael Kantor</dc:creator>
      <pubDate>Fri, 18 Sep 2026 22:51:38 +0000</pubDate>
      <link>https://dev.to/hol/breaking-openshift-console-devfile-api-lets-anyone-ssrf-your-cluster-38n4</link>
      <guid>https://dev.to/hol/breaking-openshift-console-devfile-api-lets-anyone-ssrf-your-cluster-38n4</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://hol.org/blog/cve-2026-75885-openshift-console-unauth-devfile-ssrf" rel="noopener noreferrer"&gt;HOL&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Anyone who can reach your OpenShift console Route can POST to the Devfile parser with no login, and the console pod will fetch internal URLs and chew memory until it falls over.&lt;/strong&gt; Red Hat published &lt;strong&gt;CVE-2026-75885&lt;/strong&gt; today as Important (preliminary CVSS 9.3, CWE-918). The hole is unauthenticated access to &lt;code&gt;/api/devfile/&lt;/code&gt; and &lt;code&gt;/api/devfile/samples/&lt;/code&gt; in the OpenShift console (bridge). There is no RHSA and no Fixed In Version yet. Restrict who can reach the console Route now, and watch &lt;a href="https://access.redhat.com/security/cve/CVE-2026-75885" rel="noopener noreferrer"&gt;access.redhat.com for the errata&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This is the operator write-up. The HOL Guard evidence pack for &lt;a href="https://hol.org/guard/security/cves/CVE-2026-75885?utm_source=devto&amp;amp;utm_medium=syndication&amp;amp;utm_campaign=blog_distribution&amp;amp;utm_content=cve-2026-75885-openshift-console-unauth-devfile-ssrf" rel="noopener noreferrer"&gt;CVE-2026-75885&lt;/a&gt; is the source record. Do not open a second article for the authenticated Dev Console webhook SSRF sibling &lt;strong&gt;CVE-2026-50236&lt;/strong&gt;; that one needs a login. This one does not.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks
&lt;/h2&gt;

&lt;p&gt;Red Hat’s advisory: unauthenticated access to the Devfile endpoints lets a remote attacker send crafted Devfile payloads. The console pod then makes requests to internal services (SSRF) and can reflect partial responses. Repeated large requests without a content length can drive unbounded memory growth and DoS.&lt;/p&gt;

&lt;p&gt;Bugzilla &lt;a href="https://bugzilla.redhat.com/show_bug.cgi?id=2517885" rel="noopener noreferrer"&gt;2517885&lt;/a&gt; (status NEW, Fixed In Version empty) is more specific. In &lt;code&gt;pkg/server/server.go&lt;/code&gt;, &lt;code&gt;/api/devfile/&lt;/code&gt; and &lt;code&gt;/api/devfile/samples/&lt;/code&gt; are registered with &lt;code&gt;handleFunc()&lt;/code&gt; and are &lt;em&gt;not&lt;/em&gt; wrapped in &lt;code&gt;authHandler&lt;/code&gt; / &lt;code&gt;authHandlerWithUser&lt;/code&gt; the way other &lt;code&gt;/api/*&lt;/code&gt; routes are. &lt;code&gt;DevfileHandler&lt;/code&gt; decodes an arbitrary JSON body and calls &lt;code&gt;ParseDevfileAndValidate&lt;/code&gt;. The Devfile library resolves &lt;code&gt;parent.uri&lt;/code&gt;, &lt;code&gt;Dockerfile.uri&lt;/code&gt;, and remote plugin references over HTTP from the console pod. There is no &lt;code&gt;MaxBytesReader&lt;/code&gt; / body size limit. Partial response bytes show up in the parser error string (partial-read SSRF). The reporter reproduced this on an OCP 5.0 nightly. Upstream tree: &lt;a href="https://github.com/openshift/console" rel="noopener noreferrer"&gt;openshift/console&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Red Hat scores it CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L (9.3 Important), marks mitigation as not available under their Product Security criteria, and notes scores are preliminary. Impact in plain terms: an unauthenticated caller who can hit the console Route can use the console pod as a proxy into the cluster network and can DoS the console process with large bodies.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is not in scope
&lt;/h2&gt;

&lt;p&gt;Clusters where the OpenShift console Route is not reachable from the attacker (strict network policy, private console only, no public Route) remove the unauthenticated blast radius for this CVE, but that is exposure control, not a patch. Installs that do not run the OpenShift console / bridge are out of scope. Authenticated-only Dev Console webhook SSRF tracked as &lt;strong&gt;CVE-2026-50236&lt;/strong&gt; is a different bug with a login requirement; do not treat a fix for one as coverage for the other. Non-OpenShift Kubernetes dashboards (vanilla kube-dashboard, Rancher UI, etc.) are not this CVE.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to check
&lt;/h2&gt;

&lt;p&gt;From a host that can reach the console Route, without a session cookie or OAuth token, probe whether the Devfile endpoint accepts an unauthenticated POST (expect a parser error JSON, not a 401/403 redirect to login):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Replace CONSOLE with your console Route base URL (no trailing slash)&lt;/span&gt;
&lt;span class="c"&gt;# A 401/403/login redirect is healthy. A 200/4xx parser body without auth is the bad path.&lt;/span&gt;
curl &lt;span class="nt"&gt;-sk&lt;/span&gt; &lt;span class="nt"&gt;-o&lt;/span&gt; /tmp/devfile-probe.body &lt;span class="nt"&gt;-w&lt;/span&gt; &lt;span class="s2"&gt;"HTTP %{http_code}&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-X&lt;/span&gt; POST &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;$CONSOLE&lt;/span&gt;&lt;span class="s2"&gt;/api/devfile/"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{"content":"schemaVersion: 2.2.0\nmetadata:\n  name: probe\n"}'&lt;/span&gt;

Also confirm which console image your cluster runs
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the POST returns application JSON from the Devfile parser with no auth challenge, treat the Route as exposed to CVE-2026-75885 until Red Hat ships a console build that wraps those routes in auth and caps body size. Keep the probe payload tiny and stop after one request; do not load-test production.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to fix
&lt;/h2&gt;

&lt;p&gt;There is &lt;strong&gt;no public RHSA / Fixed In Version yet&lt;/strong&gt; (Bugzilla 2517885 still NEW with an empty Fixed In Version field as of this writing). Red Hat lists mitigation as not available under their criteria. Until errata lands:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;# 1) Restrict who can reach the console Route (NetworkPolicy / ingress / private API only)
# 2) Watch for the RHSA on the CVE page, then upgrade the console operator / console image
#    https://access.redhat.com/security/cve/CVE-2026-75885
#
# After an RHSA ships, apply the errata the usual way for your OCP train, for example:
#   oc adm upgrade --to=&amp;lt;errata-recommended-version&amp;gt;
# or follow the RHSA package list for the console image digest.
#
# Re-run the unauthenticated POST probe above and confirm you get auth failure, not parser output.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Do not invent a version number. When Red Hat publishes Fixed In Version / RHSA, upgrade that build and re-check the probe. Interim control is network exposure of the console Route, not a config flag named in the advisory.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this is not
&lt;/h2&gt;

&lt;p&gt;This is not remote code execution on the cluster and not a claim that every OpenShift install on the public internet is already owned. It is unauthenticated SSRF plus resource-exhaustion DoS through two Devfile API routes on the console, with Scope Changed and Confidentiality High on Red Hat’s preliminary 9.3. It is not the authenticated Dev Console webhook SSRF (CVE-2026-50236). It is not “wait for NVD analysis before acting”: if your console Route is reachable, shrink exposure today and watch for the RHSA.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;a href="https://access.redhat.com/security/cve/CVE-2026-75885" rel="noopener noreferrer"&gt;Red Hat CVE-2026-75885&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://bugzilla.redhat.com/show_bug.cgi?id=2517885" rel="noopener noreferrer"&gt;Bugzilla 2517885&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://www.cve.org/CVERecord?id=CVE-2026-75885" rel="noopener noreferrer"&gt;CVE-2026-75885 (CVE Program)&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-75885" rel="noopener noreferrer"&gt;NVD CVE-2026-75885&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;a href="https://github.com/openshift/console" rel="noopener noreferrer"&gt;openshift/console (upstream)&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>cve</category>
      <category>openshift</category>
      <category>ssrf</category>
      <category>dos</category>
    </item>
  </channel>
</rss>
