The VeloCloud Orchestrator vulnerability (CVE-2026-16812) scores 10.0 and was exploited as a zero-day. How it works, and how to patch it.
The TeamCity RCE (CVE-2026-63077) is on CISA KEV. How unauthenticated deserialisation gives attackers your CI/CD secrets, and how to patch.
The Tomcat EncryptInterceptor bypass (CVE-2026-34486) is on CISA KEV. How a fail-open regression exposes cluster traffic, and how to patch.
The Langflow RCE (CVE-2026-9198) is under active attack. How two unauthenticated API calls give attackers full code execution.
The N-central authentication bypass (CVE-2026-18577) is under active attack. How attackers take over the RMM console, and how to patch it.
CVE-2026-20896 (CVSS 9.8): a spoofed HTTP header lets attackers become admin on Gitea’s official Docker image. Actively exploited — patch to 1.26.4 immediately.
CVE-2026-55255 is a CVSS 9.9 IDOR in Langflow letting authenticated users hijack others’ AI workflows and steal embedded API keys. Patch to 1.9.1 now.
CVE-2026-48908 (CVSS 10.0): SP Page Builder for Joomla allows unauthenticated file upload to RCE, actively exploited in the wild. Patch to 6.6.2 now.
CVE-2026-48282: Adobe ColdFusion RDS path traversal (CVSS 10.0) enables unauthenticated RCE. Actively exploited; added to CISA KEV. Patch to Update 10/21 now.
CVE-2026-57517 is a CVSS 9.8 blind SQLi in Control Web Panel (CWP) chainable to full RCE. Public PoC exists. Patch to 0.9.8.1225 now.
Writing on the Wall is a newsletter for freelance writers seeking inspiration, advice, and support on their creative journey.