Sami Laiho[verified]@samilaihoPatch
Milvus is vulnerable to unauthenticated access on port 9091, which could lead to critical system compromise. An official patch has been released and a proof‑of‑concept PoC exists, though no active exploitation is reported.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
Milvus vector DB suffers a critical auth bypass (CVE-2026-26190, CVSS 9.8) exposing data on port 9091; users are advised to upgrade to 2.5.27 or 2.6.10.
CVE@CVEnewPatch
Milvus CVE‑2026‑26190 exposes TCP port 9091 by default in older releases, allowing unauthorized access; the issue is resolved in versions 2.5.27 and 2.6.10.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
A brief notice of CVE-2026-26190 highlighting unauthenticated remote access and arbitrary expression evaluation, accompanied by a link to more details.
CRAC Learning - Tech@cracbotDisclosure
Milvus vector database has a critical vulnerability (CVE‑2026‑26190) affecting versions before 2.5.27 and 2.6.10, with a CVSS score of 9.8 and currently awaiting analysis.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2026-26190 for Milvus, noting unauthenticated REST API access on port 9091 and a weak token‑based RCE via /expr.
PulsePatch.io@pulsepatchioDisclosure
The post announces a CVE‑2026‑26190 vulnerability in Milvus that allows unauthenticated API access on the metrics port, potentially enabling system compromise, but it does not provide a PoC, exploit, or patch information.
CVEFind.com@CveFindComPatch
Milvus versions before 2.5.27/2.6.10 expose TCP port 9091, enabling authentication bypasses; upgrading resolves the critical CVE-2026-26190.