CISA issues alert on VPS.org one-click deployment templates vulnerabilities
VPS.org one-click templates use static credentials: Supabase exposes PostgreSQL on 0.0.0.0:5432 and Zulip enables session forgery.
Decision Insights Threat Desk • August 23, 2026
VPS.org one-click templates use static credentials: Supabase exposes PostgreSQL on 0.0.0.0:5432 and Zulip enables session forgery.
Decision Insights Threat Desk • August 23, 2026
Develar app-builder zipx.Unzip can allow arbitrary file overwrite on macOS via APFS Unicode normalization and symlink following.
Decision Insights Threat Desk • August 23, 2026
Analog Way Picturall Quad Compact Mark II version 3.5.8 has CVE-2026-14985 enabling root via a maintenance script. Fixed in 3.5.9.
Decision Insights Threat Desk • August 23, 2026
GNU Wget versions 1.25.0 and earlier can redirect FTP passive mode data connections using unvalidated PASV IPs, exposing internal responses.
Decision Insights Threat Desk • August 23, 2026
SGLang CVE-2026-14890 allows unauthenticated remote code execution via pickle deserialization when the expert-parallel backup subsystem is enabled.
Decision Insights Threat Desk • August 23, 2026
CVE-2026-59762, CVE-2026-59173 and CVE-2026-44909 describe an HTTP/2 DoS via stalled flow control buffering.