CERT Coordination Center
Report a vulnerability at https://kb.cert.org/vuls/report/
VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability https://kb.cert.org/vuls/id/847406
Overview
Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:Program FilesDuplicati 2 directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this
RE: https://infosec.exchange/@ESETresearch/116917582564392811
Thank you @ESETresearch@infosec.exchange for working with us to responsibly disclose this UEFI vulnerability.
Read the @certcc@infosec.exchange
Interested in doing more #UEFI vulnerability discovery work? Check out the cert-uefi-parser on GitHub and PyPI.
VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations https://kb.cert.org/vuls/id/487613
Overview
A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings.
Description
Alinto SOGo is an open-source
VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities https://kb.cert.org/vuls/id/243636
Overview
VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures.
Description
VPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services.
VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure https://kb.cert.org/vuls/id/281278
Overview
Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network
VU#762226: Plane contains multi-tenant authorization bypass vulnerability https://kb.cert.org/vuls/id/762226
Overview
The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces.
Description
Plane is an open-source project management platform that provides multi-tenant workspace isolation for users to
VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions https://kb.cert.org/vuls/id/885548
Overview
A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem https://kb.cert.org/vuls/id/326070
Overview
A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the
VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs https://kb.cert.org/vuls/id/564823
Overview
GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vuln
VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE https://kb.cert.org/vuls/id/734812
Overview
Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which allows an unauthenticated attacker to reconfigure the application to point to a remote database
VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls https://kb.cert.org/vuls/id/849433
Overview
Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million