Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2026
CVE-2026-18577
Known exploited
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CVSS Score
8.2
EPSS Score
0.025
Published
2026-08-02
CVE-2026-18556
Known exploited
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-08-01
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVSS Score
10.0
EPSS Score
0.005
Published
2026-07-30
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
CVSS Score
9.9
EPSS Score
0.003
Published
2026-07-30
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
CVSS Score
9.8
EPSS Score
0.01
Published
2026-07-30
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.
CVSS Score
9.8
EPSS Score
0.004
Published
2026-07-30
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-07-30
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-07-30
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-07-30
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-07-30


Contact Us

Shodan ® - All rights reserved