HIGH
forgekeep
CVE published 2026-09-04
CVE-2026-61699
CVE-2026-61699 debrief based on CVE Program and NVD records. A self-hosted control plane for Slack Nebula mesh VPN, nebula-mesh, has a vulnerability prior to version 0.7.1. The revocation mechanism does not update peer configurations, allowing a compromised host to remain connected for up to 30 days (agent) or 365 days (mobile). This issue allows an attacker who exfiltrates host.key+host.crt to run stock [truncated]