securityonline.info 6/8/2026, 3:20:46 AM · external

Attackers exploit CVE-2026-28318 and Zip Slip in Collibra Agent

Attackers exploit CVE-2026-28318 and Zip Slip in Collibra Agent
Developing story malware 12 articles tracked
SolarWinds Serv-U denial-of-service flaw (CVE-2026-28318) exploited in the wild
CyberSIXT Evidence Panel
Primary Source kb.cert.org
CISA KEV Listed in KEV
Patch Patch Available

A critical security vulnerability, CVE-2026-28318, has been detected in the Collibra Platform Agent, allowing remote code execution without authentication. The issue stems from inadequate handling of REST endpoints that expose sensitive functionalities. A separate Zip Slip vulnerability (CVE-2026-10621) enables attackers to exploit file extraction processes to manipulate files outside intended directories. To mitigate these risks, urgent software updates are required for both SaaS and on-premise installations. Administrators are advised to restrict REST endpoint access from public networks and consistently monitor access logs.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline