In Mattermost versions 11.1.x up to and including 11.1.2, 10.11.x up to and including 10.11.9 and 11.2.x up to and including 11.2.1 a medium severity vulnerability CVE-2026-0999 was detected. This vulnerability allows authenticated users to bypass SSO-only login requirements via userID-based authentication due to improper validation of login method restrictions. To address this issue, users should upgrade Mattermost to versions 11.3.0, 11.1.3, 10.11.10 or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-0999.
Read more CommunicationIn Mattermost versions 11.1.x up to and including 11.1.2, 10.11.x up to and including 10.11.9, 11.2.x up to and including 11.2.1 and Mattermost Plugin Zoom versions up to and including 1.11.0, a high severity vulnerability CVE-2026-0998 was detected. This vulnerability allows attackers to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and post data due to insufficient validation of user identity and post ownership in the /api/v1/askPMI endpoint. To address this issue, users should upgrade Mattermost and the Mattermost Zoom Plugin to versions 11.3.0, 11.1.3, 10.11.10 or 11.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-0998.
Read more CommunicationIn Gogs versions 0.13.4 and below a high severity vulnerability CVE-2026-25229 was detected. This vulnerability allows authenticated users with write access to one repository to modify labels belonging to other repositories due to improper repository ownership validation in the Web UI label update endpoint. To address this issue, users should upgrade Gogs to version 0.14.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25229.
Read more Developer ToolsIn Vaultwarden versions prior to 1.35.3 a medium severity vulnerability CVE-2026-26012 was detected. This vulnerability allows a regular organization member to retrieve all ciphers within an organization, regardless of collection permissions, via the /ciphers/organization-details endpoint due to missing collection-level access control enforcement. To address this issue, users should upgrade Vaultwarden to version 1.35.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26012.
Read more SecurityIn changedetection.io versions prior to 0.53.2 a medium severity vulnerability CVE-2026-25527 was detected. This vulnerability allows unauthenticated attackers to read arbitrary local application files via a path traversal flaw in the `/static/<group>/<filename>` route, due to improper validation of the group parameter. To address this issue, users should upgrade changedetection.io to version 0.53.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25527.
Read more MonitoringIn Gogs versions 0.13.4 and prior a critical severity vulnerability CVE-2026-25242 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files to the server via exposed attachment upload endpoints when the RequireSigninView setting is disabled, potentially leading to disk exhaustion, malware hosting, or abuse of the instance as a public file host. To address this issue, users should upgrade Gogs to version 0.14.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25242.
Read more Developer ToolsIn Gogs versions 0.13.4 and prior a high severity vulnerability CVE-2026-25232 was detected. This vulnerability allows authenticated attackers with write permissions to delete protected branches, including the default branch, via a direct POST request to the web interface, bypassing branch protection mechanisms and enabling privilege escalation to perform administrative-level operations. To address this issue, users should upgrade Gogs to version 0.14.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25232.
Read more Developer ToolsIn authentik versions prior to 2025.8.6, 2025.10.4 and 2025.12.4 a high severity vulnerability CVE-2026-25922 was identified. This vulnerability allows an attacker to inject a malicious SAML assertion when using a SAML Source with the “Verify Assertion Signature” option enabled but “Verify Response Signature” disabled, or when the Encryption Certificate is not configured under Advanced Protocol settings. To address this issue, users should upgrade Authentik to versions 2025.8.6, 2025.10.4, 2025.12.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25922.
Read more SecurityIn authentik versions prior to 2025.10.4 and 2025.12.4 a high severity vulnerability CVE-2026-25748 was identified. This vulnerability allows an attacker to bypass authentication by using a malformed cookie when forward authentication is enabled in the authentik Proxy Provider, particularly when used with Traefik or Caddy as a reverse proxy. Exploiting this issue prevents the setting of authentik-specific X-Authentik-* headers, potentially granting unauthorized access. To address this issue, users should upgrade authentik to versions 2025.10.4, 2025.12.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25748.
Read more Security