Tomcat’s EncryptInterceptor, meant to protect cluster traffic, can be bypassed, letting an attacker read sensitive data that should have been encrypted, no credentials needed.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
IBM Langflow Code Injection Vulnerability
Two Langflow API endpoints can be chained by anyone on the network to mint a superuser token and then execute arbitrary code, with no login required.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
An unauthenticated attacker can slip past N-central’s login checks via an alternate access path, reading and altering data on a platform many MSPs use to manage customer endpoints.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
A second, more thorough fix was needed after an earlier patch for N-central’s login flow failed to close an alternate authentication path, letting attackers seize administrator accounts outright.
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
An authenticated user with only Observer-level access to Cisco Catalyst Center’s virtual appliance can send a crafted HTTP request to gain full Administrator control.
Cisco Catalyst Center REST API Command Injection Vulnerability
An Observer-level account with API access to Cisco Catalyst Center can inject commands that run as root inside a restricted container, no admin privileges needed.
Cisco Catalyst Center Cross-Site Scripting Vulnerability
A stored input-validation flaw in Cisco Catalyst Center’s web management interface lets an attacker run script in an operator’s browser via a crafted link, exposing session data or tokens.
Cisco Catalyst Center Privilege Escalation Vulnerability
A broken access control check in Cisco Catalyst Center lets a logged-in read-only user change policy configurations that should be locked to Administrator accounts.
Cisco Catalyst Center Virtual Appliance HTTP Open Redirect Vulnerability
Cisco Catalyst Center Virtual Appliance on VMware ESXi can be tricked into redirecting management-interface users to attacker-controlled pages via a tampered HTTP request, with no fix short of upgrading.
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Two unrelated bugs in Cisco Unified CCX’s Java RMI process and CCX Editor let an unauthenticated attacker upload files, bypass authentication, and run commands as root or as an internal user, with no workaround available.