Security Feed

See the latest insights and analysis from our MDR team.
RSS for Slack
CVE-2026-84782, CVE-2026-84783, CVE-2026-84784, CVE-2026-72897
By Nevo Evenhaim | 
30 September 2026

Multiple CVEs – OpenSSL DTLS, X.509, QUIC and SSL_CTX flaws (heap leak, UAF, memory exhaustion, OOB)

OpenSSL addresses four issues: CVE-2026-84782: Retransmit of suspended WANT_WRITE can OOB-read and leak heap bytes as plaintext handshake data or crash. (Affects 1.0.2-4.0 fixed in 1.0.2zs / 1.1.1zj / 3.0.23 / 3.4.8 / 3.5.9 / 3.6.5 / 4.0.3).

CVE-2026-84783 : Extension-cache use-after-free on concurrent first use of the same trusted CA in multi-threaded TLS (Affects 4.0 fixed in 4.0.3).

CVE-2026-84784 : Unbounded RETIRE_CONNECTION_ID backlog lets a peer force ~400 MB allocation / DoS (Affects 3.4-4.0 fixed in 3.4.8 / 3.5.9 / 3.6.5 / 4.0.3).

CVE-2026-72897: OOB access after mid-handshake SSL_set_SSL_CTX() when the new context has more provider sigalgs (Affects 3.4-4.0 same fixes as CVE-2026-84784).

CVE-2026-102010
By Peleg Lampl | 
29 September 2026

CVE-2026-102010 – libstdc++ binary heap erase_if use-after-free leads to DoS

Use-after-free in GCC libstdc++: calling erase_if on a binary-heap priority queue can reallocate storage without updating an internal entry pointer. An attacker who can trigger this code path can cause an application crash (DoS) and potential memory corruption. Affected include Red Hat gcc/gcc-toolset-* packages on RHEL 6-10. Apply Red Hat updates for gcc/toolsets to mitigate.

CVE-2026-102272, CVE-2026-102273, CVE-2026-102267, CVE-2026-102268, CVE-2026-102271, CVE-2026-102272, CVE-2026-102273
By Roy Kalfon | 
29 September 2026

Multiple CVEs – PyJWT mixed-algorithm key confusion and JWKS redirect flaws enable JWT forgery and key substitution

PyJWT has multiple flaws enabling token forgery when apps allow both HMAC and asymmetric algs: CVE-2026-102268 accepts mutated public-key PEM as HMAC secret; CVE-2026-102271 accepts DER public key bytes; CVE-2026-102272 accepts UTF-8 BOM-prefixed public JWK; CVE-2026-102273 accepts public JWK containers. CVE-2026-102267 lets PyJWKClient follow attacker-influenced redirects, enabling key substitution/credential disclosure. Upgrade to 2.14.0 to mitigate.

CVE-2026-51996
By Roy Kalfon | 
29 September 2026

CVE-2026-51996 – mcp-remote getServerUrlHash code injection enables unauthenticated remote RCE

geelen/mcp-remote 0.1.16–0.1.38 allows unauthenticated remote arbitrary code execution via code injection in src/lib/utils.ts within getServerUrlHash. An attacker can exploit the network-exposed service to run attacker-controlled code, impacting confidentiality/integrity/availability. Update to 0.1.38 or disabling external access to the service to mitigate.

CVE-2026-86950
By Roy Kalfon | 
29 September 2026

CVE-2026-86950 – Apple CoreGraphics out-of-bounds write via crafted file enables arbitrary code execution

An out-of-bounds write in Apple OS file processing allows a maliciously crafted file to trigger memory corruption and achieve arbitrary code execution. Affected: `iOS/iPadOS

CVE-2026-93355
By Roy Kalfon | 
29 September 2026

CVE-2026-93355 – LiteLLM weak JWT auth allows account takeover via unverified email fallback

LiteLLM JWT auth allows a valid IdP JWT to impersonate any user by using an email-based fallback lookup without checking email_verified. An attacker can supply an unverified email matching a victim to inherit roles (incl. proxy_admin) and overwrite the victim’s identity binding for persistent admin access to API keys and user management. Affected: `

See More

Secure the new Era of AI & Realtime

Get a Demo
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS