PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61699 forgekeep CVE debrief

CVE-2026-61699 debrief based on CVE Program and NVD records. A self-hosted control plane for Slack Nebula mesh VPN, nebula-mesh, has a vulnerability prior to version 0.7.1. The revocation mechanism does not update peer configurations, allowing a compromised host to remain connected for up to 30 days (agent) or 365 days (mobile). This issue allows an attacker who exfiltrates host.key+host.crt to run stock slackhq/nebula directly, ignore the agent's 403/410 poll responses, and stay connected after the operator revokes the host. The operator-visible state (UI shows blocked, audit log records it) is misleading as the host retains full overlay reachability to every peer under its CA (or

Vendor
forgekeep
Product
nebula-mesh
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-09-08
Advisory published
2026-09-04
Advisory updated
2026-09-08

Who should care

Defenders responsible for Slack Nebula mesh VPN systems, particularly those using self-hosted control planes, should assess exposure and prioritize patching. They should also verify revocation effectiveness and monitor for unusual activity to detect potential exploitation. This includes reviewing compensating controls and ensuring that affected systems are properly secured. Security teams should track exceptions and retest remediated assets to confirm the

Why it matters

CVE-2026-61699 allows a compromised host to remain connected after revocation, posing a risk to Slack Nebula mesh VPN systems. Defenders should prioritize patching and verify revocation effectiveness.

  • Verify revocation mechanism effectiveness to prevent prolonged host connectivity
  • Patching to version 0.7.1 or later is required to fix the vulnerability
  • Monitor for unusual activity to detect potential exploitation

Technical summary

A vulnerability in nebula-mesh allows a compromised host to remain connected after revocation due to an incomplete update of peer configurations. This issue arises from the revocation mechanism not updating peer configurations, enabling an attacker who exfiltrates host.key+host.crt to maintain connectivity. The vulnerability impacts self-hosted control planes for Slack Nebula mesh VPN prior to version 0.7.1. Defenders should prioritize patching and verify revocation effectiveness to mitigate this risk. The vulnerability has been patched in version 0.7.1.

Defensive priority

Defenders should prioritize patching to version 0.7.1 or later and verify revocation effectiveness.

Recommended defensive actions

  • Patch nebula-mesh to version 0.7.1 or later
  • Verify revocation mechanism effectiveness
  • Monitor for unusual activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE Program and NVD records provide details on the vulnerability and its patch. However, additional information on affected systems and exploitation attempts is limited. The vulnerability allows a compromised host to remain connected after revocation due to an incomplete update of peer configurations. Defenders should verify revocation effectiveness and patch to version 0.7.1 or later. Limited source detail is available, so defenders should exercise caution and monitor for unusual activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61699 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61699

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61699 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61699

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.