BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

TeamViewer Fixed a Flaw That Could Override Your Session Permissions

TeamViewer fixed five client and host vulnerabilities. The lead flaw could let a remote session bypass permissions the user had explicitly denied.

Read the article ↗

Current reporting

Latest intelligence

View all articles ↗

One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access

A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN Manager without a login. Cisco says the flaw is already being exploited. Cisco disclosed CVE-2026-76504 on 30 September and gave it a critical CVSS score of 9.8. The company says an unauthenticated remote attacker can abuse improper URI encoding to bypass an authentication rule and reach the Catalyst SD-WAN Manager API with the privileges of the admin user. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue only hours later. This is not a theoretical patch-cycle item. It is a management-plane exposure with confirmed exploitation and a three-day federal remediation window. One encoded character can defeat the authentication rule The vulnerable logic is meant to restrict access to a particular API endpoint. Cisco says encoding a character in the request URI can let a crafted request slip past that rule. Cisco's example uses %6a in place of the letter j in j_security_check, but that is only an illustration. The advisory warns that an attacker can encode any one character in the request to trigger the vulnerable behaviour. Detection that looks only for /%6a_security_check will therefore be too narrow. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of system configuration. Actual remote reachability still matters. Cisco specifically warns that systems with ports exposed to the internet are at risk, and recommends preventing access from unsecured networks. Administrator API access is not the same as root A successful attack provides administrator-level access to the SD-WAN Manager API.…

30 Sep 2026 · 4 min read

The VPN Server Your Firebox Trusts Could Hand It Root Commands

WatchGuard has patched 15 vulnerabilities across supported Fireware OS branches. The most serious one turns an expected trust relationship inside out: a hostile remote VPN server can send configuration that a connecting…

30 Sep 2026 · 6 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.