Linuxsecurity Exploitation of CVE-2026-15743 in Catalyst Plugin
Article Content
- •CVE-2026-15743 allows unauthorized access to cached content.
- •Exploitation confirmed by CISA, affecting Catalyst::Plugin::Static::Simple versions up to 0.38.
- •Patches released on September 20, 2026, to mitigate the vulnerability.
CISA has confirmed the exploitation of a vulnerability (CVE-2026-15743) in the Catalyst::Plugin::Static::Simple for Perl, affecting versions up to 0.38. The flaw allows sensitive data to be exposed due to the Cache-Control header being set to 'public', enabling unauthorized access to cached content. This vulnerability impacts systems using the plugin, particularly those relying on shared reverse proxies or CDN edge caches. The issue was addressed in updates released on September 20, 2026, which allow for overriding the Cache-Control header and setting the Expires header to 0. Administrators are urged to apply the updates promptly to mitigate risks. The vulnerability was published on August 20, 2026, and is currently being exploited in the wild. Organizations using affected versions should verify their systems and apply the necessary patches immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Fedora and CVE-2026-15743 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…