PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
2026-05-14T13:24:14Z•c64992e7d6547d6528252ea2f7bb5eb6cb21e3c5d1a6744eb7225525f40d19fb
active-exploitationai-generated-exploitsandroidauthentication-bypasscpaneleximjenkinslinux-kernelnginxpatch-managementpraisonaiprivilege-escalationremote-code-executionrubyGemssupply-chainvulnerability-disclosurezero-day
What happened
The feed describes multiple high-severity vulnerabilities and active exploitation across infrastructure and supply chain. Key disclosures include PraisonAI auth bypass (CVE-2026-44338) observed targeted within hours of disclosure; Exim BDAT 'Dead.Letter' memory-corruption allowing potential code execution (CVE-2026-45185, CVSS 9.8); an 18-year-old NGINX ngx_http_rewrite_module heap overflow enabling unauthenticated RCE (CVE-2026-42945, CVSS 9.2); Fragnesia Linux kernel local privilege escalation (CVE-2026-46300, CVSS 7.8); and an actively exploited cPanel/WHM authentication-bypass (CVE-2026-?
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c64992e7d6547d6528252ea2f7bb5eb6cb21e3c5d1a6744eb7225525f40d19fb
- Enrichment time
- 2026-05-14T13:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.