chiprook
← Security
SecuritySeptember 24, 2026, 04:00

JumpServer patches QVD-2026-65008 AccessKey disclosure flaw

In September 2026, open-source bastion host JumpServer fixed vulnerability QVD-2026-65008 (CVSS 8.8), which let an unauthenticated attacker retrieve all users' AccessKeys and temporary tokens. Chinese vendor Qianxin counted roughly 19,000 at-risk assets in China; fixes shipped in LTS builds v3.10.23 and v4.10.19.

JumpServer patches QVD-2026-65008 AccessKey disclosure flaw
#JumpServer
Read next
Security

Microsoft unveils Integrated Security Operations Center in Defender for AI agents

Security

Oracle shifts agent controls to the data layer

Security

RemControl Android banking malware targets Europe and Canada

Security

New EDR Evasion Stack Slips Process Injection Past Defenses