Security Feed

See the latest insights and analysis from our MDR team.
RSS for Slack
CVE-2026-53710
By Nevo Evenhaim | 
16 September 2026

CVE-2026-53710 – mcp-contextforge-gateway RestrictedPython getattr sandbox bypass enables arbitrary code execution

mcp-contextforge-gateway =1.0.2.

CVE-2026-82049
By Roy Kalfon | 
16 September 2026

CVE-2026-82049 – CPython tarfile extraction filter flaw enables hardlink-to-symlink path escape

In CPython 3.13 and earlier, tarfile data/tar extraction filters mishandle crafted archives with a hard link to a symbolic link. Extraction can change mode/mtime of a file outside the destination directory or expose that file’s contents inside the extracted tree. Upgrade to 3.14.0b1 or later.

CVE-2026-91924
By Nevo Evenhaim | 
16 September 2026

CVE-2026-91924 – pgweb missing authorization on `/api/connect` allows arbitrary DB connections

pgweb through 0.17.0 leaves POST /api/connect unguarded even when connect-backend authorization is configured. A network attacker with low privileges can submit arbitrary DB connection strings plus a custom session identifier to bypass resource-to-database mapping, enabling unauthorized access to databases and internal services. Upgrade from `

CVE-2026-91995
By Nevo Evenhaim | 
16 September 2026

CVE-2026-91995 – pig auth bypass in `/register/password` enables account takeover

pig (pkg:github/pig-mesh/pig) before 4.1.0 allows unverified password changes via /register/password because current-password verification results are discarded. Remote unauthenticated attackers can submit a target username with any “current password” to overwrite credentials (including admin) and gain full administrative control. Upgrade to 4.1.0+ (fix commit ce958668).

CVE-2026-71133
By Yonatan Lewkowicz | 
15 September 2026

Oracle Critical Security Patch Update – September 2026

Oracle released a Critical Security Patch Update containing 673 new security patches across multiple product families, covering vulnerabilities in Oracle code and bundled third-party components. Oracle reports ongoing exploitation attempts against customers who failed to apply earlier fixes. Review prior CPU/CSPU advisories, verify affected products in the Patch Availability Document, and apply cspusep2026 patches without delay on actively-supported versions.

CVE-2026-61559
By Yonatan Lewkowicz | 
15 September 2026

CVE-2026-61559 – @zereight/mcp-gitlab SSRF via X-GitLab-API-URL leaks Private-Token

SSRF/token exfiltration in @zereight/mcp-gitlab when ENABLE_DYNAMIC_API_URL=true: attacker sets X-GitLab-API-URL to an arbitrary host, and the server uses it as the base for outbound GitLab API calls, attaching the victim Private-Token to each fetch. Affected `>=0.0.1,

See More

Secure the new Era of AI & Realtime

Get a Demo
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS