DEV Community

#vulnerabilitymanagement

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

GitLab CVE-2026-85706: When a Path Traversal Lands in the Software Delivery Chain

Comments
4 min read
The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation

The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation

Comments
3 min read
Penetration Test Findings That Never Get Fixed: Running a Retest Programme

Penetration Test Findings That Never Get Fixed: Running a Retest Programme

Comments
2 min read
When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

When the Artifact Repository Is the Target: JFrog Artifactory and the Software Supply Chain Chokepoint

Comments
3 min read
When the AI Gateway Becomes the Weakest Link: Command Execution in LiteLLM's MCP Test Endpoints

When the AI Gateway Becomes the Weakest Link: Command Execution in LiteLLM's MCP Test Endpoints

Comments
4 min read
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

1
Comments
4 min read
A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

A One-Character Token Was Enough: LiteLLM and the Credential Concentration Problem in AI Gateways

Comments
4 min read
Edge Appliance Zero-Days: What the SonicWall SMA1000 Chain Teaches About Patch Windows

Edge Appliance Zero-Days: What the SonicWall SMA1000 Chain Teaches About Patch Windows

Comments
4 min read
The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders

The Management Plane Is the Attack Plane: What Three Clusters on One Cisco FMC Tell Defenders

Comments
4 min read
Extended Support Isn't Extended Security: Managing Vulnerabilities in ELS Linux Environments

Extended Support Isn't Extended Security: Managing Vulnerabilities in ELS Linux Environments

5
Comments
7 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

Comments
3 min read
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

Comments
3 min read
The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter

The Cisco FMC Authentication Bypass Shows Why Management Planes Are the Real Perimeter

Comments
4 min read
Using CISA KEV Deadlines as a Triage Clock for Vulnerability Backlogs

Using CISA KEV Deadlines as a Triage Clock for Vulnerability Backlogs

Comments
2 min read
Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call

Why the Same Old Bugs Keep Getting Exploited: CISA's Secure-by-Design Wake-Up Call

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.