CRITICAL
tobychui
CVE published 2026-09-25
CVE-2026-100390
CVE-2026-100390 debrief based on the supplied source corpus. The CVE record was published on 2026-09-25T21:17:22.637Z and has not been modified since then. This vulnerability affects Zoraxy versions 3.2.3 through 3.3.4, allowing unauthenticated attackers to bypass IP-based access controls by spoofing their source IP address using IPv6 connections. Defenders responsible for Zoraxy instances, particularly t [truncated]