PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

2026-05-14T13:24:14Zc64992e7d6547d6528252ea2f7bb5eb6cb21e3c5d1a6744eb7225525f40d19fb
active-exploitationai-generated-exploitsandroidauthentication-bypasscpaneleximjenkinslinux-kernelnginxpatch-managementpraisonaiprivilege-escalationremote-code-executionrubyGemssupply-chainvulnerability-disclosurezero-day

What happened

The feed describes multiple high-severity vulnerabilities and active exploitation across infrastructure and supply chain. Key disclosures include PraisonAI auth bypass (CVE-2026-44338) observed targeted within hours of disclosure; Exim BDAT 'Dead.Letter' memory-corruption allowing potential code execution (CVE-2026-45185, CVSS 9.8); an 18-year-old NGINX ngx_http_rewrite_module heap overflow enabling unauthenticated RCE (CVE-2026-42945, CVSS 9.2); Fragnesia Linux kernel local privilege escalation (CVE-2026-46300, CVSS 7.8); and an actively exploited cPanel/WHM authentication-bypass (CVE-2026-?

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c64992e7d6547d6528252ea2f7bb5eb6cb21e3c5d1a6744eb7225525f40d19fb
Enrichment time
2026-05-14T13:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure · Baitaphish