CVE-2026-16713
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a secur
CVSS
4.3
Medium
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Published: Aug 13, 2026 · Last modified: Aug 17, 2026 · CWE-1327
0.2%EPSS · 30 days0.3%
2026-08-142026-08-28
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8245610.0 CRI—
———argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.10hCVE-2026-165039.1 CRI24.4%
——7Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.26dCVE-2026-478738.0 HIG9.3%
——3The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier29d