CVE-2026-90823 FatPipe MPVPN, WARP, and IPVPN appliances running end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default.
CVE-2026-90822 FatPipe MPVPN, WARP, and IPVPN appliances running end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The [truncated]