,

Vulnerability Watch No67

🚨 DeepSeek Harness Authentication Bypass Grants Full Agent Control
Teams running DeepSeek Harness should upgrade immediately because this flaw can provide complete control of the agent environment. Restrict access to the control-plane API until patched.
CVE-2026-82533 affects DeepSeek Harness before 0.1.2-alpha.1 due to an authentication bypass in its local HTTP control-plane API. The vulnerability is CRITICAL with CVSS 9.6 and can allow attackers to gain full agent control, execute privileged commands, alter session policies, and retrieve stored conversations.
🔗 Read more 🔗
Source: NVD

🛑 MongoDB Router Resource Exhaustion Bug Can Cause Service Disruption
MongoDB administrators should patch exposed router deployments quickly, especially systems reachable from untrusted networks. No authentication is required, making externally accessible instances a priority.
CVE-2026-82075 is an uncontrolled resource consumption weakness in the request-handling path of the MongoDB sharded-cluster router process. The vulnerability is HIGH with CVSS 7.5 and allows unauthenticated network users to consume CPU resources and degrade availability without affecting confidentiality or integrity.
🔗 Read more 🔗
Source: NVD

💥 MongoDB Storage Configuration Flaw Risks Crashes and Code Execution
MongoDB operators should patch deployments where users have write permissions. Prioritize environments with many database users because exploitation could extend beyond denial of service.
CVE-2026-82071 is an insufficient validation issue in MongoDB Server storage engine configuration options. The vulnerability is HIGH with CVSS 8.1 and can allow authenticated users with write privileges to trigger an out-of-bounds memory write, causing crashes with potential for arbitrary code execution.
🔗 Read more 🔗
Source: NVD

🔓 MongoDB Authorization Bug Could Allow Administrative Takeover
MongoDB administrators should patch urgently and verify authorization settings during startup. Internet-accessible database deployments should receive immediate attention.
CVE-2026-82067 is an improper handling of case sensitivity in MongoDB Server configuration validation. The HIGH severity vulnerability has CVSS 8.1 and may leave authorization disabled during startup, allowing unauthenticated network users to perform arbitrary administrative operations.
🔗 Read more 🔗
Source: NVD

💣 MongoDB Replica Set Assertion Issue Triggers Remote Crashes
MongoDB teams should patch affected replica set members quickly, particularly those exposed to untrusted networks. Production clusters should account for the availability impact during remediation.
CVE-2026-82064 is a security issue in MongoDB Server that can cause denial of service on a specific type of replica set member. The vulnerability is HIGH with CVSS 7.5 and allows an unauthenticated network user to trigger server process termination.
🔗 Read more 🔗
Source: NVD

🧠 MongoDB Query Memory Bug May Cause Crashes and Corruption
MongoDB administrators should patch systems where users have database read access. Shared database environments should be prioritized due to the memory corruption risk.
CVE-2026-82061 is a use-after-free security issue in MongoDB Server query execution memory tracking. The HIGH severity vulnerability has CVSS 8.1 and may allow authenticated users with read privileges to cause crashes or potential memory corruption.
🔗 Read more 🔗
Source: NVD

🔑 MongoDB LDAP Authorization Flaw Could Elevate Privileges
Organizations using MongoDB with LDAP authorization should patch and review access mappings. Check for unexpected privilege changes after remediation.
CVE-2026-82053 affects MongoDB LDAP authorization integration where pooled LDAP connections can retain stale authentication identities. The HIGH severity vulnerability has CVSS 8.1 and may allow authenticated users to receive unintended elevated privileges through incorrect role assignments.
🔗 Read more 🔗
Source: NVD

🤖 NVIDIA Triton Authorization Gap Exposes AI Workloads
Teams operating Triton inference servers should patch promptly and review access controls around AI services. Limit unnecessary exposure of inference endpoints until fixes are applied.
CVE-2026-47625 affects NVIDIA Triton Inference Server for Linux due to missing authorization controls. The vulnerability is HIGH with CVSS 7.5 and successful exploitation may lead to information disclosure, data tampering, and denial of service.
🔗 Read more 🔗
Source: NVD

🚨 FortiSandbox Access Control Flaw Exposes Sensitive Information
FortiSandbox customers should patch immediately and review exposure of HTTP-accessible services. Critical access control issues should be handled as urgent remediation items.
CVE-2026-26084 is an improper access control vulnerability affecting Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS versions listed in the advisory. The issue is CRITICAL with CVSS 9.9 and may allow attackers to access sensitive information through crafted HTTP requests.
🔗 Read more 🔗
Source: NVD

🔥 Ivanti Neurons for ITSM Deserialization Bug Enables Remote Code Execution
Ivanti Neurons for ITSM administrators should patch immediately and investigate exposed systems. Remote unauthenticated code execution flaws require urgent action.
CVE-2026-12745 is a Deserialization of Untrusted Data vulnerability affecting Ivanti Neurons for ITSM before 2026.2. The vulnerability is CRITICAL with CVSS 9.8 and allows a remote unauthenticated attacker to execute arbitrary code on the server.
🔗 Read more 🔗
Source: NVD