PatchSiren

forgekeep CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH forgekeep CVE published 2026-09-04

CVE-2026-61699

CVE-2026-61699 debrief based on CVE Program and NVD records. A self-hosted control plane for Slack Nebula mesh VPN, nebula-mesh, has a vulnerability prior to version 0.7.1. The revocation mechanism does not update peer configurations, allowing a compromised host to remain connected for up to 30 days (agent) or 365 days (mobile). This issue allows an attacker who exfiltrates host.key+host.crt to run stock [truncated]