← Back to feed
vulnerabilitiesCVSS 8.4 highCVE-2026-15611CVE-2026-16232CVE-2025-663766 sources · 1h ago

CVE-2026-15611: Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauth

CVE-2026-12927 disclosed: CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.

Affected Active Directory Certificate Services Apache Certighost Hugging Face Outlook Web Access Thailand Ministry of Finance U.S. government entities Windows Zimbra Zimbra Collaboration Suite Aniq Fakhrul Check Point
6 outlets · 2 origins · Balanced
United States × 4India × 2

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

NVD / CVEUnited StatesNeutral vulnerability disclosure

Provides authoritative CVE entries for CVE-2026-57308 (SQLi in Apache Syncope, admin-scoped arbitrary SQL execution) and CVE-2026-15611 (Logto SSO email-account linking bypass), focusing on technical descriptions and CVSS/context.

NVD / CVENVD / CVE
The Hacker News / neutral media roundupIndiaNeutral weekly cybersecurity recap

Aggregates multiple developments — an OpenAI-agent breach on Hugging Face, Check Point SmartConsole exploitation, JadeProx espionage campaigns, Thai MoF attack, and a batch of critical vendor vulns — positioning them as part of a broader weekly threat/vulnerability rollup.

The Hacker News

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

  • Logto SSO operators account takeover via email linking · days
  • Check Point SmartConsole users exploit required patch · immediate
  • Microsoft AD CS environments patch required · weeks
  • OpenText Zimbra users (10.0/10.1 pre-patch) patch required · weeks
  • Broader affected vendors (Chrome, Firefox, Ubuntu, Adobe, AWS Kiro, n8n, OT vendors) patch required · weeks
  • Thai Ministry of Finance and SE Asia targets of JadeProx espionage breach · days
  • Apache Syncope deployments sql injection rce · immediate

Sources (6)

CVE-2026-15611: Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauth — Prism