VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities
2026-08-05T20:52:02Z•47ad00cca0fc2aff5cdab2c2a82bc60a46d0356f7b51740fa30d645157fa52bd
CVE-2026-15611CVE-2026-15612CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-16637CVE-2026-16771AI/LLMBOLAIDORSSRFaccount-takeoverarbitrary-file-overwriteauthentication-bypassauthorization-bypasscloud-deploymentcredential-disclosuredefault-credentialsidentity-managementinsecure-deserializationmacOSnetwork-deviceremote-code-executionsecret-exposureunpatchedvulnerability
What happened
CERT/CC advisories published July 23–31, 2026 describe multiple vulnerabilities across VPS deployment templates, SGLang, foreUP, Develar app-builder, OPeNDAP Hyrax, Arris BGW210-700 gateways, and Logto. Issues include unauthenticated remote code execution, SSRF, credential and secret disclosure, default-password exposure, authentication and authorization bypasses, insecure file extraction, account takeover, arbitrary file overwrite, and sensitive data exposure. Several vulnerabilities are remotely exploitable with little or no authentication, and SGLang reportedly had no available patches at].
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 47ad00cca0fc2aff5cdab2c2a82bc60a46d0356f7b51740fa30d645157fa52bd
- Enrichment time
- 2026-08-05T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.