Security vulnerabilities I have responsibly disclosed. All findings were reported to the affected vendors and patched before public disclosure.
| CVE / ID | Product | Summary | Severity | Date | References |
|---|---|---|---|---|---|
| CVE-2026-34724 | Zammad | server-side template injection to RCE via the new AI Agent feature | High (8.7) | 2026-06-03 | CVE, GHSA, Blog post |
| CVE-2026-34719 | Zammad | direct-request server-side request forgery (SSRF) via webhooks | High (8.3) | 2026-06-03 | CVE, GHSA, Blog post |
| CVE-2026-34718 | Zammad | stored XSS / phishing via data: URI HTML sanitizer bypass | Moderate (5.3) | 2026-06-03 | CVE, GHSA, Blog post |