Find notable cyber news and cases, enriched with sources, timelines, and signals.

Issabel Framework security patch for CVE-2026-89026

Security Patch Release
First reported
Last updated
Happening score
H score 50
1 unique sources, 1 articles

Summary

Hide ▲

A security patch for Issabel Framework was pushed on August 1, 2026 to fix CVE-2026-89026, closing an unauthenticated OS command execution path tied to a hard-coded JWT signing key. The update moves the JWT key out of the application code and into /etc/issabel.conf, reducing the risk across affected installations. That remediation is directly relevant because the flaw was already under active exploitation.

Related Happenings

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Adobe security patch release for CVE-2026-48395

Security Patch Release
H score39 First: 01.08.2026 10:12 Last: 01.08.2026 10:12 Sources 1

About this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...

SimpleHelp security update for CVE-2026-48558

Security Patch Release
H score65 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

About this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...

CISA Apache ActiveMQ CVE-2026-34197 mitigation order

Advisory/Mitigation
H score71 First: 21.04.2026 14:17 Last: 21.04.2026 14:17 Sources 1

About this happening: CISA ordered FCEB agencies to secure Apache ActiveMQ servers by April 30 after CVE-2026-34197 was confirmed actively exploited. The flaw can allow arbitr...

Elementor Ally 4.1.0 security patch release (CVE-2026-2313)

Security Patch Release
H score59 First: 11.03.2026 21:38 Last: 11.03.2026 21:38 Sources 1

About this happening: Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...

Timeline

  1. 16.09.2026 18:50 2 articles · 2h ago

    Issabel Framework patch moves JWT key into /etc/issabel.conf

    Mitigation Patch Update

    A patch for Issabel Framework was pushed on August 1, 2026 to remediate CVE-2026-89026 by replacing the hard-coded HS256 JWT signing key in pbxapi index.php with a key stored in /etc/issabel.conf, reducing the unauthenticated remote OS command execution risk across installations.

    Show sources
  2. 16.09.2026 18:50 1 articles · 2h ago

    Shadowserver Foundation observes exploitation of CVE-2026-89026 in Issabel Framework

    Exploitation Observed

    Shadowserver Foundation first observed exploitation of CVE-2026-89026 in Issabel Framework on September 9, 2026, indicating active abuse of the shared JWT signing key weakness that can let unauthenticated remote attackers forge bearer tokens and trigger arbitrary OS commands through Asterisk.

    Show sources