Tag
critical
advisory
Unauthenticated Access to backpropagate UI via Authentication Bypass (CVE-2026-48797)
7 TTPs 1 CVE 3 IOCsAn authentication bypass vulnerability in `backpropagate` versions >= 1.1.0 and < 1.2.0 allows unauthenticated attackers to gain full control over the Reflex web UI, even when HTTP Basic authentication is ostensibly enabled via the `--auth` flag, permitting data exfiltration, arbitrary training runs, HuggingFace Hub push, disk-fill DoS, and sensitive path discovery.
backpropagate +1
authentication-bypass
critical-vulnerability
supply-chain
data-exfiltration
denial-of-service
web-ui
machine-learning
reflex
7t
1c
3i
critical
advisory
Cisco IOS XE Web UI Implant Access via CVE-2023-20198
2 rules 1 TTP 1 CVE 4 IOCsExploitation of the Cisco IOS XE Web UI vulnerability (CVE-2023-20198) through crafted POST requests to obtain unauthorized access and maintain persistence on compromised devices.
PoC
IOS XE
cisco-ios-xe
web-ui
cve-2023-20198
implant
2r
1t
1c
4i
updated