PatchDay Alert

CVE

CVE-2026-6887

0field notes · 1digest CVSS 9.8


Daily digests

Borg SPM 2007 has an unauthenticated SQL injection bug that lets a remote attacker read, modify, or delete anything in the database. No credentials needed. CVSS 9.8. This product's sales ended in 2008, so there will be no patch.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.