Security Feed
CVE-2026-39364 – Vite dev server `server.fs.deny` bypass via query params leaks files
Vite dev server access control can be bypassed: files blocked by server.fs.deny (e.g., .env, *.crt) are still served with HTTP 200 when requests append ?raw, ?import&raw, or ?import&url&inline. Affects: vite >= 7.1.0, < 7.3.2 and >= 8.0.0, < 8.0.5, plus vite-plus < 0.1.16. Upgrade to 7.3.2 or 8.0.5 (or vite-plus 0.1.16+) to mitigate.
CVE-2026-12944 – IBM Langflow OSS SSRF scanner bypass enables root (UID=0) Python code execution
IBM Langflow OSS 1.0.0 through 1.10.0 lets authenticated attackers submit components with socket/urllib imports that bypass an incomplete scanner blocklist, enabling SSRF and arbitrary Python execution as root. Impact includes AWS credential theft via IMDSv1, container file exfiltration, and lateral movement to Docker-network services (PostgreSQL/Redis). Upgrade to 1.10.1 to mitigate.
CVE-2026-76461 – Cisco Secure Email Gateway email parsing SQL injection enables root command execution
Cisco AsyncOS for Cisco Secure Email Gateway has an email parsing flaw where crafted emails inject malicious SQL due to insufficient input validation. Unauthenticated remote attackers can send a crafted message to run arbitrary SQL that leads to OS command execution with root privileges. Affected versions include 14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007. Apply Cisco mitigations/updates.
CVE-2026-73496 & CVE-2026-73497 – MCP Atlassian path traversal file upload and DNS rebinding SSRF expose server secrets and internal services
In mcp-atlassian, client-controlled attachment file_path (Confluence tools and Jira attachments) is uploaded without workspace confinement, letting write-tool clients exfiltrate MCP server files/Atlassian creds in remote HTTP/SSE/multi-user deploys (`
CVE-2026-90919 – LightLLM Config Server unsafe pickle deserialization in WebSocket enables unauthenticated RCE
LightLLM through 1.2.0 is vulnerable to unauthenticated RCE in the Config Server /visual_register WebSocket endpoint, which passes the first client frame directly to pickle.loads(). An attacker who can reach the Config Server port can send a crafted serialized payload (via reduce) to execute arbitrary code with Config Server process privileges. Restrict network access to the Config Server and upgrade when a fix is available.
CVE-2026-82434 – Apache Storm leaks ZooKeeper auth payload to read-only topology viewers and logs
In Apache Storm, when ZooKeeper auth is enabled, Nimbus served storm.zookeeper.topology.auth.payload verbatim to callers with read-only topology permissions, exposing a non-read-only ZooKeeper credential. The leaked credential can forge/remove cluster state (worker heartbeats, backpressure, error state). Client/SASL handlers also logged the payload. Affects `3.0.0–
Deep Threat Research
Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract









