Six distinct command injection, file inclusion, and authentication bypass vulnerabilities were disclosed between September 24–26, 2026, affecting Frictionless, Cambium, Lantronix, WordPress Visual Composer, Netis routers, and Netlink routers. Each report describes a separate product flaw with no common thread beyond being security exploits.
CVE-2026-94611 - authentik: Stored credentials are readable with view permission alone CVE ID : CVE-2026-94611 Published : 24 septembre 2026 17:17 | 21 minutes ago Description : authentik is an open-source identity provider. 2, aut...
Multiple open-source projects released updates between 2026-09-10 and 2026-09-12: Authentik rolled out versions 2026.8.2, 2026.2.7, and 2026.5.7 with security patches and bug fixes, while Nextcloud Server v34.0.4 addressed stability improvements. All updates focus on security hardening and bug resolution for self-hosted deployments.
21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.