THREAT OPS › Threat News
Threat Intelligence News
11903 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-10848 (HIGH 7.0) — The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then scnvd · 2026-08-02
- [qilin] Mairie de Drancy posted to leak siteransomware_live · 2026-08-02
- [NVD] CVE-2026-9856 (HIGH 7.1) — A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dinvd · 2026-08-02
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-02
- [NVD] CVE-2026-65321 (CRITICAL 9.8) — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that bacnvd · 2026-08-02
- [NVD] CVE-2026-10774 (LOW 2.4) — Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but subnet_keynvd · 2026-08-02
- Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actorahnlab · 2026-08-02
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-02
- [krybit] www.dcpartner.co.za posted to leak siteransomware_live · 2026-08-02
- [krybit] nigeria.asa-international.com posted to leak siteransomware_live · 2026-08-02
- [krybit] www.ville-rinxent.fr posted to leak siteransomware_live · 2026-08-02
- [krybit] countrymotors.com.mx posted to leak siteransomware_live · 2026-08-02
- [SilentRansomGroup] Moses & Singer posted to leak siteransomware_live · 2026-08-02
- [krybit] www.buzztrading104.co.za posted to leak siteransomware_live · 2026-08-02
- [NVD] CVE-2026-68583 (MEDIUM 5.4) — luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrnvd · 2026-08-02
- [NVD] CVE-2026-68582 (MEDIUM 6.5) — Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the callnvd · 2026-08-02
- [NVD] CVE-2026-68581 (HIGH 8.1) — Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a targenvd · 2026-08-02
- [NVD] CVE-2026-68580 (HIGH 7.5) — FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket nvd · 2026-08-02
- [NVD] CVE-2026-68579 (CRITICAL 9.6) — FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStrnvd · 2026-08-02
- [NVD] CVE-2026-68578 (HIGH 7.5) — ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary Javanvd · 2026-08-02
- [NVD] CVE-2026-67357 (HIGH 7.5) — ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-Arcadenvd · 2026-08-02
- [NVD] CVE-2026-67356 (HIGH 8.8) — ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScripnvd · 2026-08-02
- [NVD] CVE-2025-71401 (MEDIUM 5.9) — better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to rnvd · 2026-08-02
- [NVD] CVE-2025-71400 (HIGH 7.1) — better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkeynvd · 2026-08-02
- [NVD] CVE-2025-71399 (HIGH 8.6) — Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), thnvd · 2026-08-02
- Re: Some Changes to GNOME Security Trackingoss_sec · 2026-08-02
- [CVE requested] iwd <= 3.12: stack buffer overflow in the 802.11k beacon report handler, plus three parser/validation bugs (no fix upstream)oss_sec · 2026-08-02
- [qilin] Wire Products posted to leak siteransomware_live · 2026-08-02
- [NVD] CVE-2026-12231 (MEDIUM 6.4) — The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authennvd · 2026-08-02
- [NVD] CVE-2026-18573 (MEDIUM 6.5) — A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due nvd · 2026-08-02
- [NVD] CVE-2026-18572 (MEDIUM 6.5) — Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request thanvd · 2026-08-02
- [NVD] CVE-2026-18571 (MEDIUM 6.6) — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to mnvd · 2026-08-02
- [NVD] CVE-2026-18570 (MEDIUM 5.4) — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executonvd · 2026-08-02
- [NVD] CVE-2026-16540 — The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, tonvd · 2026-08-02
- [NVD] CVE-2026-16292 — The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that nvd · 2026-08-02
- [NVD] CVE-2026-16291 — The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.nvd · 2026-08-02
- [NVD] CVE-2026-16285 — The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.nvd · 2026-08-02
- [NVD] CVE-2026-16273 — The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged usnvd · 2026-08-02
- [NVD] CVE-2026-16261 — The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's passwonvd · 2026-08-02
- [NVD] CVE-2026-16256 — The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers tonvd · 2026-08-02
- [NVD] CVE-2026-16064 — The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and punvd · 2026-08-02
- [NVD] CVE-2026-16063 — The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to innvd · 2026-08-02
- [NVD] CVE-2026-16062 — The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in thenvd · 2026-08-02
- [NVD] CVE-2026-15939 — The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission nvd · 2026-08-02
- [NVD] CVE-2026-15385 — The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can nvd · 2026-08-02
- [NVD] CVE-2026-15248 — The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.nvd · 2026-08-02
- [NVD] CVE-2026-15241 — The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, whennvd · 2026-08-02
- [NVD] CVE-2026-15236 — The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of thenvd · 2026-08-02
- [NVD] CVE-2026-15206 — The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to selecnvd · 2026-08-02
- [NVD] CVE-2026-15151 — The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin befnvd · 2026-08-02
- [NVD] CVE-2026-14938 — The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages annvd · 2026-08-02
- [NVD] CVE-2026-14864 — The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged usnvd · 2026-08-02
- [NVD] CVE-2026-14841 — The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricknvd · 2026-08-02
- [NVD] CVE-2026-14817 — The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to injnvd · 2026-08-02
- [NVD] CVE-2026-13389 — The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPrnvd · 2026-08-02
- [NVD] CVE-2026-12586 — The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the accounvd · 2026-08-02
- [NVD] CVE-2026-11872 — The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings tnvd · 2026-08-02
- [NVD] CVE-2025-15675 — The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Scripting attacks that execute nvd · 2026-08-02
- [NVD] CVE-2026-9335 (MEDIUM 6.5) — A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpnvd · 2026-08-02
- [CRPxO] Encore Enterprises, Inc. posted to leak siteransomware_live · 2026-08-02
- Lean 4 kernel soundness bug: forging proofs via nested inductive projections (0 = 1 demonstrated)oss_sec · 2026-08-02
- [NVD] CVE-2026-8457 (CRITICAL 9.8) — The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signatnvd · 2026-08-02
- [NVD] CVE-2026-18352 (HIGH 7.5) — The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, whinvd · 2026-08-02
- [NVD] CVE-2026-13339 (HIGH 7.5) — The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, whichnvd · 2026-08-02
- [shinyhunters] Alcon Inc. posted to leak siteransomware_live · 2026-08-02
- [shinyhunters] Lumenis Ltd. posted to leak siteransomware_live · 2026-08-02
- [shinyhunters] Questel SAS posted to leak siteransomware_live · 2026-08-02
- [thegentlemen] Philippine Savings Bank posted to leak siteransomware_live · 2026-08-01
- [NVD] CVE-2026-55735 — Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it onvd · 2026-08-01
- [NVD] CVE-2026-55734 — Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guardian/permissions.ex and program routines 'nvd · 2026-08-01
- [NVD] CVE-2026-55733 — Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binaries to String.to_atom/1. Wnvd · 2026-08-01
- [NVD] CVE-2026-54894 — Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary binaries to String.to_atomnvd · 2026-08-01
- [play] The Butcher Brothers posted to leak siteransomware_live · 2026-08-01
- [play] Sigma Plastics Group posted to leak siteransomware_live · 2026-08-01
- [play] Cambridge Management posted to leak siteransomware_live · 2026-08-01
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutesthehackernews · 2026-08-01
- [incransom] quantinuum.com posted to leak siteransomware_live · 2026-08-01
- [Global Secret Group] Vernon & Waldrep posted to leak siteransomware_live · 2026-08-01
- [GHSA] GHSA-mjrx-74jh-7xgw (high) — Duplicate Advisory: Guzzle: Host-only cookie scope is not preservedgithub_advisories · 2026-08-01
- Re: 33 Vulnerabilities in cJSONoss_sec · 2026-08-01
- [qilin] The Saturday Evening Post posted to leak siteransomware_live · 2026-08-01
- [qilin] Commercial Furniture Interiors posted to leak siteransomware_live · 2026-08-01
- [qilin] Dienst Pack Systems posted to leak siteransomware_live · 2026-08-01
- [qilin] Ceragres posted to leak siteransomware_live · 2026-08-01
- [qilin] Pointe Property Group posted to leak siteransomware_live · 2026-08-01
- [qilin] Schreiner Trockenbau GmbH posted to leak siteransomware_live · 2026-08-01
- [NVD] CVE-2026-67354 (MEDIUM 5.9) — guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generatnvd · 2026-08-01
- [NVD] CVE-2026-67353 (MEDIUM 5.3) — guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data invd · 2026-08-01
- [NVD] CVE-2026-67352 (HIGH 7.6) — luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes Janvd · 2026-08-01
- [NVD] CVE-2026-67344 (MEDIUM 4.3) — ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only rnvd · 2026-08-01
- [NVD] CVE-2026-67343 (HIGH 8.8) — ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-nvd · 2026-08-01
- [NVD] CVE-2026-67342 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by nvd · 2026-08-01
- [NVD] CVE-2026-67341 (CRITICAL 9.8) — ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intendenvd · 2026-08-01
- [NVD] CVE-2026-67340 (CRITICAL 9.8) — ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that nvd · 2026-08-01
- [NVD] CVE-2026-67339 (MEDIUM 5.3) — guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies thatnvd · 2026-08-01
- [NVD] CVE-2026-67338 (MEDIUM 6.1) — JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary Javanvd · 2026-08-01
- [NVD] CVE-2026-67337 (MEDIUM 6.5) — better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session cnvd · 2026-08-01
- [NVD] CVE-2026-67336 (HIGH 8.7) — better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codenvd · 2026-08-01
- [NVD] CVE-2026-67335 (MEDIUM 5.3) — better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessionsnvd · 2026-08-01
- [NVD] CVE-2026-67334 (LOW 3.8) — better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for upnvd · 2026-08-01