Security Feed

See the latest insights and analysis from our MDR team.
RSS for Slack
CVE-2026-86140
By Mor Plada | 
5 September 2026

CVE-2026-86140 – libxml2 stack-based buffer overflow in `xmlSnprintfElements()` via `strcat`

libxml2 before 2.15.4 contains a stack-based buffer overflow in xmlSnprintfElements() (valid.c) due to unsafe strcat usage. The CVSS vector is AV:L/AC:L/PR:N/UI:N, indicating local attack surface with no privileges required; exploitation can corrupt memory and compromise confidentiality/integrity. Upgrade libxml2 to 2.15.4+ to remediate.

CVE-2026-85656
By Mor Plada | 
5 September 2026

CVE-2026-85656 – Amazon Linux log4j-cve-2021-44228-hotpatch OS command injection allows root

OS command injection in Amazon Linux log4j-cve-2021-44228-hotpatch lets a local user run arbitrary commands as root by abusing a Java process whose executable path contains embedded newline characters. Affected: versions < 1.3-9.amzn2. Remediate by upgrading the package to 1.3-9.amzn2 or later per Amazon advisories.

CVE-2026-85623
By Ron Shemesh | 
4 September 2026

aaif-goose goose recipe extensions and retry checks allow arbitrary command execution

goose executes arbitrary shell commands embedded in recipe stdio extensions and retry.checks without security inspection. Malicious recipes delivered over the network can bypass the recipe security scan (extensions/retry config not inspected) and run commands as the local user executing goose. Affected: `aaif-goose/goose

CVE-2026-85625
By Ron Shemesh | 
4 September 2026

sift.js prototype pollution enables JavaScript execution via `$where` query operator

sift (pkg:npm/sift) `

CVE-2026-85595
By Ron Shemesh | 
4 September 2026

Traefik authentication bypasses via digestAuth and TLS option conflict fallback

traefik 0 < 2.11.55 and `3.0.0

CVE-2026-79707
By Ron Shemesh | 
4 September 2026

Google Agent Development Kit builder endpoint path traversal enables arbitrary file read

A path traversal in the google-adk builder endpoint lets an unauthenticated remote attacker read arbitrary files via a crafted file_path query parameter. Affected: Google Cloud Agent Development Kit (ADK) for Python >= 1.9.0, < 1.22.0 (1.9.0–1.21.0). Impact is high confidentiality loss through file disclosure. Upgrade to 1.22.0+.

See More

Secure the new Era of AI & Realtime

Get a Demo
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS