Xentrika Blog

Security insights, straight from the field.

Practical knowledge on penetration testing, cybersecurity, and digital defense from the Xentrika team.

Latest

CVE-2026-19478: Critical GitLab GraphQL Code Injection

Published August 18, 2026

CVE-2026-19478 is a critical CVSS 9.4 GitLab GraphQL code injection vulnerability that can allow unauthenticated attackers to modify or delete public projects and user data. No verified public PoC or active exploitation has been confirmed as of August 18, 2026.

CVE-2026-64633: Veeam ONE Agent RCE Needs No Password

Published August 6, 2026

A CVSS 10.0 code-injection vulnerability in Veeam ONE allows a remote, unauthenticated attacker to execute code on the agent host. No active exploitation is known, but affected systems should be upgraded to 13.1.0.7034 immediately.

CVE-2026-68771: ComfyUI Pickled Its Way to Unauthenticated RCE

Published August 3, 2026

An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.