HKUDS vulnerabilities
4 CVEs tracked
The HKUDS vendor appears in our reporting in the context of its 'nanobot' tool, where multiple critical vulnerabilities have been identified in versions up to 0.2.1. Key themes include OS command injection (CVE-2026-19243), improper access controls (CVE-2026-19244), information disclosure (CVE-2026-19245), and Server-Side Request Forgery (CVE-2026-19246). Defenders should prioritize patching for these CVEs on any systems running nanobot, apply restrictive network controls, and monitor for anomalous tool behavior.
Azərbaycanca: HKUDS vendor-u hesabatlarımızda özünün 'nanobot' aləti ilə əlaqədar görünür, hansı ki, 0.2.1 versiyasına qədər bir neçə kritik boşluq aşkarlanıb. Əsas mövzular əməliyyat sistemi əmri inyeksiyası (CVE-2026-19243), icazə nəzarətindəki qüsurlar (CVE-2026-19244), məlumat sızması (CVE-2026-19245) və Server-Side Request Forgery (CVE-2026-19246) zəiflikləridir. Müdafiəçilər 'nanobot' istifadə edən sistemlərdə bu boşluqlar üçün yamaqları prioritetləşdirməli, şəbəkə səviyyəsində məhdudlaşdırıcı qaydaları tətbiq etməli və alətin gözlənilməz davranışlarını izləməlidirlər.
This vendor's CVEs4
This hub is built from skopnix's own reporting on HKUDS: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.