
Fedora released Vaultwarden fixes for Fedora 43 and 44 to address CVE-2026-27801 two-factor authentication bypass and CVE-2026-27803 unauthorized collection management flaws, Linuxsecurity reported. https://threatcluster.io/cluster/critical-security-flaws-in-vaultwarden-affecting-fedora-43-a-e75ff84b
Post summary
Fedora has issued patches for Vaultwarden to mitigate CVE-2026-27801 (two-factor authentication bypass) and CVE-2026-27803 (unauthorized collection management), with no mention of active exploitation or PoC.



