AFDS-2026-041
Auth bypass in a widely used VPN concentrator's session handling

Malformed session tokens allowed an unauthenticated attacker to assume an existing session under specific load conditions. Fixed in the vendor's next point release.

HIGH · CVSS 9.1 Aug 2026
AFDS-2026-037
Firmware downgrade path in an IoT gateway's update signing

Signature verification could be bypassed by replaying an older signed image, re-exposing previously patched vulnerabilities.

HIGH · CVSS 8.6 Jul 2026
AFDS-2026-029
Race condition in a CI provider's secret-scoping logic

A narrow timing window allowed a job in one pipeline to briefly read secrets scoped to a concurrent, unrelated pipeline.

MEDIUM · CVSS 6.4 Jun 2026
AFDS-2026-024
Improper certificate pinning in a mobile banking SDK

Pinning could be silently disabled through a debug flag left reachable in release builds, permitting traffic interception.

MEDIUM · CVSS 5.9 May 2026
AFDS-2026-018
Predictable token generation in a payment SDK's test mode

Test-mode tokens were generated from a low-entropy seed, making them guessable within a practical timeframe.

LOW · CVSS 3.9 Apr 2026
AFDS-2026-011
Deserialization flaw in a message-queue broker's plugin loader

Untrusted plugin manifests were deserialized before validation, enabling remote code execution on the broker host.

HIGH · CVSS 9.4 Mar 2026
AFDS-2026-004
Information disclosure via verbose error responses in a public API gateway

Stack traces returned on malformed requests revealed internal hostnames and library versions.

LOW · CVSS 4.1 Feb 2026
AFDS-2025-052
Privilege escalation via misconfigured default role in a data warehouse product

A default analyst role inherited administrative query permissions on newly created schemas.

MEDIUM · CVSS 6.8 Dec 2025

Reporting something?

Have a finding for us to review?

disclose@afdigitalsec.com
Contact the team