Continue reading the full briefing.
Operational focus: Use flow, DNS, authentication, and configuration-change logs to validate containment.
Open the original NIST National Vulnerability Database record
CVE-2026-70485: Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
## Summary Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally routable. That test operates on the literal IPv6 address and does not look at the IPv4 address embedded inside it. On a deployment…
Why it matters: GitHub Advisory Database open-webui participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Identify exposed management interfaces and confirm the exact firmware or software version.
CVE-2026-67245: A path traversal vulnerability was found in the VPN Clients on the…
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this issue to write an uploaded certificate file outside the intended VPN certificate directory, subject to process privileges and…
Why it matters: CVE-2026-67245 may control a traffic or administration path that other systems implicitly trust, making reachability and management-plane exposure more important than the headline score alone.
What to verify: Inventory affected models and firmware, close public administration paths, compare routes and configuration, inspect flow and DNS logs, and validate connectivity after the upgrade.
Operational focus: Restrict administrative access to trusted networks and rotate credentials after suspected compromise.
Open the original NIST National Vulnerability Database record
USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these…
Why it matters: Ubuntu Security Notices may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Use flow, DNS, authentication, and configuration-change logs to validate containment.
CVE-2026-55685: React Router is a router for React. In versions 7.0.0 through 7.17.0,…
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode () or Data…
Why it matters: CVE-2026-55685 may control a traffic or administration path that other systems implicitly trust, making reachability and management-plane exposure more important than the headline score alone.
What to verify: Inventory affected models and firmware, close public administration paths, compare routes and configuration, inspect flow and DNS logs, and validate connectivity after the upgrade.
Operational focus: Identify exposed management interfaces and confirm the exact firmware or software version.
Open the original NIST National Vulnerability Database record
CVE-2026-64642: Next.js is a React framework for building full-stack web applications. In versions…
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.
Why it matters: CVE-2026-64642 may control a traffic or administration path that other systems implicitly trust, making reachability and management-plane exposure more important than the headline score alone.
What to verify: Inventory affected models and firmware, close public administration paths, compare routes and configuration, inspect flow and DNS logs, and validate connectivity after the upgrade.
Operational focus: Restrict administrative access to trusted networks and rotate credentials after suspected compromise.
Open the original NIST National Vulnerability Database record
Containment and firmware plan
Start at the internet edge and management plane. Preserve configurations, restrict administration paths, patch supported firmware, and rotate credentials where compromise cannot be ruled out.
- Compare KEV and vendor advisories with firewalls, routers, VPNs, gateways, and switches in inventory.
- Remove public management exposure and require approved administrative paths.
- Patch or replace unsupported edge devices and preserve configurations before changes.
- Rotate device credentials and review new accounts, routes, policies, and tunnels.
- Validate segmentation and centralized logging after remediation.
Traffic and management signals
Check firmware, exposed management paths, configuration changes, new accounts, tunnels, routes, and independent logs.
- Identify exposed management interfaces and confirm the exact firmware or software version.
- Restrict administrative access to trusted networks and rotate credentials after suspected compromise.
- Use flow, DNS, authentication, and configuration-change logs to validate containment.
Network team takeaway
Edge risk falls when management access is private, firmware is supported, credentials are rotated after doubt, and network changes are visible outside the device.
References used in this briefing
- CISA Known Exploited Vulnerabilities: CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- NIST National Vulnerability Database: CVE-2026-66747: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every…
- GitHub Advisory Database: CVE-2026-70485: Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
- NIST National Vulnerability Database: CVE-2026-67245: A path traversal vulnerability was found in the VPN Clients on the…
- Ubuntu Security Notices: USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities
- NIST National Vulnerability Database: CVE-2026-55685: React Router is a router for React. In versions 7.0.0 through 7.17.0,…
- NIST National Vulnerability Database: CVE-2026-64642: Next.js is a React framework for building full-stack web applications. In versions…
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

