Issue no. 42 · The security zine
Security is all about context.
Practical security thinking for systems that increasingly write, deploy, and operate themselves. Fewer buzzwords. Better evidence. Occasional memes.
CVE-2026-13355 Meta Box Meta Box AIO★CVE-2026-92969 realmag777 HUSKY – Products Filter for WooCommerce Professional★CVE-2026-95511 OpenPrinting CUPS★CVE-2026-15801 Red Hat CRI-O★CVE-2026-80110 Red Hat Red Hat Certificate System★CVE-2026-93962 Kamailio Kamailio★CVE-2026-93990 libexpat Expat★CVE-2026-93991 argoproj Argo Workflows★CVE-2026-93993 mistralai Mistral Vibe★CVE-2026-94106 James Heinrich getID3Patch forecast · Sep 22
Known-exploited vulnerabilities are in the wild. Patch like it is raining.
Field report · sweep 03 · 25 contacts on the board
Advisory desk
Known exploitation already skipped the prioritization meeting.
Meta Box Meta Box AIO
A chained authorization flaw in Meta Box AIO (and the standalone Meta Box Frontend Submission and Meta Box User Profile plugins) lets unauthenticated attackers overwrite any page with a crafted shortcode and register an Administrator account. Fixed in Meta Box AIO 3.12.0.
realmag777 HUSKY – Products Filter for WooCommerce Professional
An unauthenticated local file inclusion flaw in the HUSKY Products Filter for WooCommerce Professional plugin lets visitors include and execute arbitrary .php files via the 'shortcode' parameter, because the only nonce check uses a value emitted into every front-end page.
OpenPrinting CUPS
A privilege escalation flaw in CUPS with the cups-filters serial backend lets a local user in the lpadmin group point a printer's device URI at an arbitrary path, so the root-privileged backend writes attacker-controlled data to any file. A public proof of concept exists.
Live demo · try it right here
Find leaked secrets without leaking them.
Paste code, config, or logs below. 112 detectors run entirely in your browser and return redacted findings, reasoned risk scores, and rotation guidance. Nothing uploads. Nothing phones home.
Inspect source material
No upload step exists. Files are read by your browser, scanned in memory, and discarded when the tab closes.
Findings
Ready when you are.
Add source material on the left. Results are pattern matches, not proof that a credential is active.
Latest transmissions
For the work after the scanner finishes yelling.
A field guide to agentic vulnerability management (with an actual off switch)
A practical operating model for introducing agents without confusing automation, authority, and accountability.
Finding vulnerabilities is getting cheaper. The backlog has noticed.
AI compresses the cost of discovery, but the expensive parts of vulnerability management still begin after the finding exists.
The vulnerability ticket is an interface, not a filing cabinet
A useful vulnerability record should help an owner decide and act—not merely preserve scanner output.
exhibit A: the backlog