PatchDay Alert

CVE

CVE-2026-6886

0field notes · 1digest CVSS 9.8


Daily digests

Borg SPM 2007 has an authentication bypass that lets any remote attacker log in as any user without credentials. CVSS 9.8. Combined with CVE-2026-6887 (SQL injection in the same product), this thing is completely wide open. No patch is coming since the product has been end-of-life since 2008.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.