PatchSiren

FatPipe Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL FatPipe Networks CVE published 2026-09-17

CVE-2026-90823

CVE-2026-90823 FatPipe MPVPN, WARP, and IPVPN appliances running end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default.

CRITICAL FatPipe Networks CVE published 2026-09-17

CVE-2026-90822

CVE-2026-90822 FatPipe MPVPN, WARP, and IPVPN appliances running end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The [truncated]