Critical N
A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization’s entire password vault, including live two-factor authentication codes. Tracked as CVE-2026-15580, the issue received a CVSS v4.0 base score of 9.4 and affected Passportal extension version 3.49.5. N-able released version 3.49.6 […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
