AI Security Typebot 3.18.0: account takeover and server file read in a chatbot platform
CVE-2026-62862 and CVE-2026-62865 combine weak login codes with file exfiltration through Nodemailer. A technical review and Typebot 3.18.0 response plan.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security CVE-2026-62862 and CVE-2026-62865 combine weak login codes with file exfiltration through Nodemailer. A technical review and Typebot 3.18.0 response plan.
AI Security TransitionParser used an unrestricted unpickler, then the first allowlist trusted whole modules. Analysis of RCE, versions 3.10.0 and 3.10.3, and NLP pipeline defence.
Vulnerabilities and CVEs Three Moderate and six Low issues include double free, heap overflow, DoS and skipped AEAD-tag verification. Exposure analysis and fixed releases 4.0.2–3.0.22.
Threats and Incidents An anonymous form passed sender_name into a Fluid View as template source. Analysis of active exploitation, ViewHelpers, versions 10.9.3/12.6.1/13.2.1 and response.
Vulnerabilities and CVEs An authenticated control-panel user could pass behavior/event configuration through condition.config. Analysis of Yii, versions 4.18.2 and 5.10.6, and response.
AI Security Six loaders trusted model remote code. Analysis of trust_remote_code, version 2.12.0, model-launch privileges and AI worker isolation.
Cloud, Infrastructure and DevSecOps Under certain conditions, a low-privileged authenticated user could move from a package path to code execution. Analysis of affected versions, risk and response.
Vulnerabilities and CVEs The WordPress plugin replaced native permission callbacks with a login check. A Subscriber could create an Administrator or change an admin password.
Cloud, Infrastructure and DevSecOps A User-role tenant could bypass validation of nested Metalink URLs, trigger SSRF and reach root command execution on a shared KVM compute host.
AI Security A per-request tool list was not a complete authorisation boundary. Technical analysis of CVE-2026-59318, prompt injection, upgrades and telemetry.
Vulnerabilities and CVEs An anonymous visitor could alter styling data for arbitrary posts, including drafts and private content. Analysis of nonces, object authorisation and version 7.8.1.
Vulnerabilities and CVEs An invalid input key was compiled as a regex without exception handling. Analysis of FETCH, EXISTS, DELETE, version 2.0.0 and safe dynamic-pattern design.
Vulnerabilities and CVEs A missing capability check in settings import let a Subscriber modify WordPress options. Analysis of escalation, version 2.8.25 and incident traces.
AI Security CVE-2026-77775 and 77776 expose reflected SSRF with Authorization forwarding and cross-user LLM memory access in network-reachable deployments.
Vulnerabilities and CVEs CVE-2026-77645, 77646 and 77644 affect Windchill, FlexPLM and WRR. A technical plan for patching, segmentation, hunting and MethodServer defence.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.