under embargo
- zdi-can-31611:
- cvss 7.6, lifts 10-17-2026
- zdi-can-32336
- cvss 6.5, lifts 11-14-2026
- zdi-can-32339
- cvss 6.5, lifts 11-29-2026
- zdi-can-32342
- cvss 6.5, lifts 11-29-2026
- zdi-can-32710
- cvss 5.3, lifts 12-24-2026
- zdi-can-32416
- cvss 5.0, lifts 12-26-2026
2026
- cve-2026-8023: cvss 7.5 - path traversal
- zephyr’s http server static filesystem handler fails to normalize or reject
..path segments, allowing unauthenticated remote attackers to read files outside the configured web root. both http/1.1 and http/2 are affected.
- zephyr’s http server static filesystem handler fails to normalize or reject