SecureDrop Workstation — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 22, 2026
Last Seen
August 22, 2026

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-49996: securedrop-proxy origin limitation can be bypassed with redirects [LOW] CVSS 3.7 Exploit Intelligence - Recent CVEs / 1d SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is — exploit-intel.com · August 22, 2026
  • CVE-2026-49996 - Exploits & Severity — Feedly · August 22, 2026

CVSS v3.1 Breakdown