View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

OpenYak unauthenticated CSRF chain enables remote code execution

🔓 CVEs & KEV

The CVE roundup for today includes several high-severity vulnerabilities across container runtimes, APIs, and network devices.

  • CVE-2026-46409 — CVSS 9.6 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
  • CVE-2026-50540 — CVSS 9.6 — Kata Containers: Config Path Annotation Arbitrary File Loading
  • CVE-2026-47243 — CVSS 9.2 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
  • CVE-2026-48169 — CVSS 8.8 — PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
  • CVE-2026-45808 — CVSS 7.1 — OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypass
  • CVE-2026-9031 — CVSS 6.8 — Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check