Ctrlaltnod Multiple High-Severity Vulnerabilities Discovered in API and Identity Services
Article Content
Browse articles
Three critical vulnerabilities have been identified in various services, affecting users and systems. CVE-2025-11573 presents an infinite loop issue with a CVSS score of 7.5, while CVE-2025-59146 is a high-severity SSRF vulnerability with a CVSS score of 8.5. Additionally, CVE-2025-59218 is a critical privilege escalation flaw in Azure Entra ID, rated CVSS 9.6, allowing unauthenticated access.
Ask AI about this cluster
Answers cite the sources they use
Updated 211d ago How this analysis works
More articles in this cluster (3)
Following this threat?
Track CVE-2025-11573 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
High-Risk SSRF Vulnerability in Privoce VoceChat Server Disclosed A critical vulnerability, CVE-2026-100893, has been identified in the Privoce VoceChat Server up to version 0.5.36. This vulnerability allows remote attackers to exploit the open_graph::fetch function by manipulating the URL parameter, leading to server-side request forgery (SSRF). The attack can be executed without…
CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data A vulnerability identified as CVE-2026-92602 affects the TDuck survey form through version 5.3, allowing authenticated attackers to exploit unvalidated webhook URLs. This Server-Side Request Forgery (SSRF) vulnerability can lead to unauthorized access to sensitive survey submissions and potential data exfiltration.…