New MCP server — Bring vulnerability intelligence into your AI
Back to feed

CVE-2026-16527

NVDCIRCL

Published Jul 30, 2026 · today

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVSS scores

  • v3.17.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Potentially impacted assets

See if this affects your attack surface

Latest trending attack

Criticaltoday

CVE-2026-48020 - Traefik - Unauthenticated Auth Bypass via Path Traversal

Traefik is an open-source HTTP reverse proxy and load balancer that routes and distributes network traffic across multiple backend services. CVE-2026-48020 Critical security flaw discovered in Traefik versions before 2.11.48, 3.6.19, and 3.7.3 that allows attackers without proper credentials to bypass authentication protections designed to keep certain areas of a website or application private. The vulnerability works by exploiting how Traefik processes web addresses — specifically, an attacker can craft a request with special characters (like ".." or its encoded version "%2e%2e") that tricks the system into stripping away security checks and granting access to restricted admin panels and internal configuration pages that should have remained protected. This means that sensitive backend systems and administrative tools could be exposed to unauthorized access, posing a significant risk to organizations using affected versions of Traefik.

Take 15 minutes to discover our platform with our experts

PatrowlIntel platform screenshot