⚠️ undici Cache Bug Enables Cross-Origin Data Exposure
Teams using affected undici versions should upgrade to undici 8.10.2 quickly, especially if cache or deduplication interceptors are used directly on Client or Pool. The reported authentication bypass scenario makes this a priority patch.
CVE-2026-85152 affects undici 8.10.0 through 8.10.2, where cache and request-deduplication keys omit the destination origin. The HIGH severity flaw (CVSS 7.4) can cause responses from one trusted origin to be returned to another, enabling cross-origin information disclosure and cache poisoning.
🔗 Read more 🔗
Source: NVD
🔒 undici TLS Validation Bypass Hits BalancedPool
Applications using BalancedPool with custom TLS callbacks or connectors should upgrade to undici 7.29.1 or 8.10.2. Review TLS assumptions carefully because rejected peers may be accepted under affected configurations.
CVE-2026-84961 affects undici BalancedPool versions 7.24.1 through 7.29.1 and 8.0.0 through 8.10.2. The HIGH severity vulnerability (CVSS 7.4) causes function-valued TLS options to be discarded, potentially bypassing custom certificate validation checks.
🔗 Read more 🔗
Source: NVD
🚨 PowerJob Worker Unauthenticated RCE Exposes Servers
PowerJob deployments should be patched or isolated immediately. An unauthenticated remote code execution path should be treated as an emergency, especially for internet-exposed workers.
CVE-2026-75430 affects PowerJob Worker version 5.1.2 and likely earlier versions. The CRITICAL severity flaw (CVSS 9.8) exposes the /worker/deployContainer endpoint without authentication, allowing remote attackers to execute arbitrary code.
🔗 Read more 🔗
Source: NVD
🧩 IBM ContextForge Session Leak Exposes Data
Organizations running affected ContextForge MCP Gateway versions should apply fixes promptly and review whether sensitive session data may have been exposed.
CVE-2026-18489 affects IBM ContextForge MCP Gateway Translate utility versions up to 1.0.8. The HIGH severity vulnerability (CVSS 7.4) allows remote attackers to obtain sensitive information from other sessions due to improper session data isolation.
🔗 Read more 🔗
Source: NVD
🔑 IBM ContextForge Bug Allows Credential Theft
Patch affected ContextForge deployments quickly and review privileged access paths. Any environment using authenticated users with sensitive data access should prioritize remediation.
CVE-2026-18486 affects IBM ContextForge MCP Gateway versions up to v1.0.7. The HIGH severity flaw (CVSS 8.8) allows remote authenticated attackers to obtain sensitive credentials and escalate privileges through improper validation of jq filters.
🔗 Read more 🔗
Source: NVD
🛡️ IBM i Authentication Flaw Risks Unauthorized Access
IBM i administrators should apply available fixes and review remote access controls. Prioritize systems exposed to untrusted networks.
CVE-2026-18221 affects IBM i versions 7.6, 7.5, 7.4, and 7.3. The HIGH severity vulnerability (CVSS 8.1) allows remote attackers to gain unauthorized access due to improper validation of client-supplied authentication parameters.
🔗 Read more 🔗
Source: NVD
⚠️ IBM i DDM Dispatcher Bug Allows Transaction Manipulation
Patch IBM i systems using affected DDM functionality and review authorization boundaries. Systems handling critical database transactions should be treated as high priority.
CVE-2026-18175 affects IBM i versions 7.6, 7.5, 7.4, and 7.3. The HIGH severity flaw (CVSS 8.1) allows remote attackers to manipulate database transactions due to improper authorization in the DDM target dispatcher.
🔗 Read more 🔗
Source: NVD
🐛 smol-toml Parser Hang Creates Denial of Service Risk
Developers using smol-toml to parse untrusted TOML should upgrade to 1.7.1 immediately. This is especially important for services processing user-controlled configuration data.
CVE-2026-85730 affects smol-toml versions before 1.7.1. The HIGH severity vulnerability (CVSS 8.2) can trigger an infinite loop when parsing specially crafted TOML input, consuming application resources and causing denial of service.
🔗 Read more 🔗
Source: NVD
🌐 IBM ContextForge SSRF Bug Exposes Internal Data
Patch affected ContextForge installations and review outbound request controls. SSRF issues can expose internal services and sensitive network resources if left unresolved.
CVE-2026-77822 affects IBM ContextForge MCP Gateway. The HIGH severity vulnerability (CVSS 8.2) allows remote authenticated attackers to obtain sensitive information through server-side request forgery via DNS rebinding.
🔗 Read more 🔗
Source: NVD
🚨 PowerJob Predictable JWT Key Enables Remote Code Execution
PowerJob Server operators should patch immediately and rotate authentication secrets. Treat exposed instances as potentially compromised due to the ability to forge authentication tokens.
CVE-2026-75431 affects PowerJob Server version 5.1.2 and likely earlier releases. The CRITICAL severity flaw (CVSS 9.1) uses a predictable JWT signing key for HS256 authentication, allowing remote attackers to execute arbitrary code.
🔗 Read more 🔗
Source: NVD
🔥 Voltronic Power Firmware Upload Flaw Allows Root RCE
Patch or isolate affected Voltronic devices immediately. An unauthenticated root-level RCE should be considered a critical exposure for any reachable device.
CVE-2026-44402 affects Voltronic Power SNMP Web Pro 1.1. The CRITICAL severity vulnerability (CVSS 9.8) allows unauthenticated remote attackers to upload crafted firmware archives and execute arbitrary commands as root.
🔗 Read more 🔗
Source: NVD
📂 IBM Langflow Flaw Leaks Server Secrets
Langflow OSS users should patch urgently and investigate possible secret exposure. Rotate compromised credentials and keys if affected systems may have processed malicious file paths.
CVE-2026-19306 affects IBM Langflow OSS versions 1.0.0 through 1.11.2. The HIGH severity vulnerability (CVSS 7.7) allows authenticated attackers to read arbitrary server files, including secret material, JWT keys, databases, and tenant uploads.
🔗 Read more 🔗
Source: NVD