CVE-2026-46711
Published 30 September 2026 · tracked since 1 October 2026
Description
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin ch
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102377 HIGH 8.8
- CVE-2026-100512 CRITICAL 9.8
- CVE-2026-62308 CRITICAL 9.1
- CVE-2026-55494 CRITICAL 9.8
- CVE-2026-55181 CRITICAL 9.4
- CVE-2026-47571 HIGH 7.8
- CVE-2026-47573 HIGH 7.8
- CVE-2026-47575 HIGH 7.8
- CVE-2026-47570 HIGH 7.8
- CVE-2026-47559 HIGH 7.8