SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16504

CRITICAL · CVSS 9.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The vulnerability arises from the deployment of the VPS.org one-click Zulip template, which includes a hardcoded application signing key, a default database password of "zulip," and disables HTTPS by default. This configuration significantly increases the risk of unauthorized access and data breaches, as sensitive information can be easily exploited by attackers. Organizations utilizing this deployment should prioritize immediate remediation to secure their Zulip instances and protect against potential exploitation.

CVE
CVE-2026-16504
Severity
CRITICAL
CVSS
9.8
EPSS
0.35%

Original NVD Description

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.