Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Two things live here.
Advisories — a running brief on the vulnerabilities that matter to people running network and edge infrastructure. Every CISA KEV addition, plus critical flaws in firewalls, VPN gateways, routers and management planes. What it is, what to do about it, and what to tell your leadership — in that order. Sources and the checks every post passes are set out in the methodology.
The workshop — longer write-ups from a home lab: virtualisation, self-hosted AI image and speech generation, build automation, and the things that broke on the way. Slower, and considerably less urgent.
Latest advisories
Zammad GmbH Zammad Session Fixation Vulnerability
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Improper limitation of a pathname to a restricted directory
An unauthenticated attacker can send crafted HTTP or HTTPS requests to write arbitrary files onto a Fortinet device, bypassing path restrictions and NULL-byte filtering, with no login required.
Fortinet FortiMail Path Traversal Vulnerability
An unauthenticated attacker can send crafted requests to FortiMail’s web interface and write arbitrary files onto the underlying system, with no login required and active exploitation already confirmed.
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
A hex-encoding trick in URI handling lets an unauthenticated attacker slip past an access restriction on a Catalyst SD-WAN Manager API endpoint and operate with full admin rights.
Apple Multiple Products Out-of-Bounds Write Vulnerability
A memory-corruption bug in Apple’s CoreGraphics image-parsing framework lets a crafted file trigger arbitrary code execution on iPhones, iPads and Macs, with a known targeted-exploitation report.
From the workshop
Three AI reviews of the same project, and where they disagreed
I gave three AI models the same data about a project of mine and asked each, separately, why it was not growing. The consensus turned out to be the least useful part.
Auditing a homelab after it breaks: what the documentation got wrong
After a failure I went through my own infrastructure line by line and compared it to my notes. Six things were wrong, and all six were wrong in the same direction.
Proxmox on a second-hand workstation
Why an old dual-socket workstation beats a mini PC for a home hypervisor, and the three decisions that determine whether the thing is still running in a year.