CISA warns PayRange Android 7.0.7 has TLS and WebView issues
PayRange Android 7.0.7 has two WebView vulnerabilities involving invalid TLS certificates and JavaScript injection via on-path interception.
Decision Insights Threat Desk • August 23, 2026
PayRange Android 7.0.7 has two WebView vulnerabilities involving invalid TLS certificates and JavaScript injection via on-path interception.
Decision Insights Threat Desk • August 23, 2026
Duplicati v2.3.0.1 can allow arbitrary code execution when installed outside C:\Program Files\Duplicati 2\, tied to CVE-2026-16157.
Decision Insights Threat Desk • August 23, 2026
SGLang has six vulnerabilities (CVE-2026-15969 to CVE-2026-15978) enabling RCE, SSRF, credential leaks, and model weight exfiltration.
Decision Insights Threat Desk • August 23, 2026
RDK-B WebUI rdkb-2025q4-kirkstone has flaws including JWT signature verification errors and memory corruption that can bypass authentication and cause DoS.
Decision Insights Threat Desk • August 23, 2026
OPeNDAP Hyrax CVE-2026-16637 involves SSRF via unvalidated HTTP redirects that bypass AllowedHosts and leak User-Id and Echo-Token.
Decision Insights Threat Desk • August 23, 2026
Plane versions 1.3.0 and earlier have a multi-tenant authorization bypass in the asset-management API that can allow cross-workspace access, delete, or duplicate of assets.