VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

2026-08-05T20:52:02Z47ad00cca0fc2aff5cdab2c2a82bc60a46d0356f7b51740fa30d645157fa52bd
CVE-2026-15611CVE-2026-15612CVE-2026-15657CVE-2026-15658CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-16637CVE-2026-16771AI/LLMBOLAIDORSSRFaccount-takeoverarbitrary-file-overwriteauthentication-bypassauthorization-bypasscloud-deploymentcredential-disclosuredefault-credentialsidentity-managementinsecure-deserializationmacOSnetwork-deviceremote-code-executionsecret-exposureunpatchedvulnerability

What happened

CERT/CC advisories published July 23–31, 2026 describe multiple vulnerabilities across VPS deployment templates, SGLang, foreUP, Develar app-builder, OPeNDAP Hyrax, Arris BGW210-700 gateways, and Logto. Issues include unauthenticated remote code execution, SSRF, credential and secret disclosure, default-password exposure, authentication and authorization bypasses, insecure file extraction, account takeover, arbitrary file overwrite, and sensitive data exposure. Several vulnerabilities are remotely exploitable with little or no authentication, and SGLang reportedly had no available patches at].

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
47ad00cca0fc2aff5cdab2c2a82bc60a46d0356f7b51740fa30d645157fa52bd
Enrichment time
2026-08-05T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.