CISA issues advisory on OPeNDAP Hyrax SSRF and credential disclosure
OPeNDAP Hyrax CVE-2026-16637 involves SSRF via unvalidated HTTP redirects that bypass AllowedHosts and leak User-Id and Echo-Token.
Records are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • August 23, 2026
OPeNDAP Hyrax CVE-2026-16637 involves SSRF via unvalidated HTTP redirects that bypass AllowedHosts and leak User-Id and Echo-Token.
Decision Insights Threat Desk • August 23, 2026
Plane versions 1.3.0 and earlier have a multi-tenant authorization bypass in the asset-management API that can allow cross-workspace access, delete, or duplicate of assets.
Decision Insights Threat Desk • August 23, 2026
Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and…
Decision Insights Threat Desk • August 23, 2026
Xerte Online Toolkits reports two vulnerabilities that can lead to remote code execution, fixed in v3.15.5 and v3.14.6.
Decision Insights Threat Desk • August 23, 2026
OpenCart v4.2.0.0 extension installer mishandles ZIP paths, enabling file writes to webroot and remote code execution; CVE-2026-18412.
Decision Insights Threat Desk • August 23, 2026
foreUP REST API flaws disclose Finix merchant credentials and allow IDOR access to other customers’ profiles, tokens, and billing history.
Decision Insights Threat Desk • August 23, 2026
Develar app-builder zipx.Unzip can allow arbitrary file overwrite on macOS via APFS Unicode normalization and symlink following.
Decision Insights Threat Desk • August 23, 2026
SGLang CVE-2026-14890 allows unauthenticated remote code execution via pickle deserialization when the expert-parallel backup subsystem is enabled.
Decision Insights Threat Desk • August 23, 2026
Alinto SOGo versions prior to 5.12.8 contain an XSS flaw in how they render ICS (iCalendar) DESCRIPTION content, allowing an SVG payload with JavaScript to execute in the webmail interface and…
Decision Insights Record • August 19, 2026
Third Circuit held Pindrop qualifies as a financial institution under Illinois BIPA via GLBA, exempting it from BIPA consent requirements.
Decision Insights Record • August 18, 2026
Allot will chair a Post-Quantum Communications consortium supported by Israel’s Innovation Authority to develop PQC, QKD, and hybrid approaches.
Decision Insights Record • August 18, 2026
Teleport added Linux Desktop support as a protected resource in its Infrastructure Identity Platform, applying unified controls to workstations.
Decision Insights Record • August 18, 2026
Illumio said it was named a Leader and “Customer Favorite” in Forrester’s Microsegmentation Solutions Q3 2026.
Decision Insights Record • August 18, 2026
Concentric AI made a vision-model feature available in its Semantic Intelligence platform to detect passports and U.S. driver licenses by visual signatures.
Decision Insights Record • August 7, 2026
Broadcom updated VMware vDefend and Avi Load Balancer for VMware Cloud Foundation, adding lateral security, on-prem and air-gapped support, and WAAP/API protection.
Decision Insights Record • August 7, 2026
Cequence Security said NTT DOCOMO deployed its application and API protection platform and that it launched Cequence AI Gateway in Japan.
Decision Insights Record • August 7, 2026
Infoblox completed its Kentik acquisition, adding real-time network intelligence and observability to support trusted data for AI-driven operations.
Decision Insights Record • August 7, 2026
Synack said NatJack research targets NAT design assumptions, reports two CVEs, and described no single patch plus interim mitigations.
Decision Insights Record • August 6, 2026
Cequence Security said NTT DOCOMO deployed its application and API protection platform and the firm launched Cequence AI Gateway in Japan.
Decision Insights Record • August 6, 2026
Broadcom updated VMware vDefend and Avi Load Balancer for VMware Cloud Foundation, adding ATP 1-2-3, on-prem malware, air-gapped support, and AI assistant.
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.