CVE@CVEnewGeneral
The text references CVE-2026-40177 as a 2FA bypass vulnerability in Ajenti’s core plugin, citing the CVE record link but offering no details on exploitation, tool, or patch.
Daily Security Review@securitydailyrDisclosure
The post announces the discovery of two critical command injection CVEs (CVE-2026-40176 and CVE-2026-40177) affecting Composer’s Perforce VCS driver, warning that many PHP applications are at risk.
CCB Alert@CCBalertDisclosure
The statement announces a critical authentication bypass vulnerability (CVE-2026-40177) in Ajenti Core, supplying its CVSS score and linking to a GitHub security advisory.
PulsePatch.io@pulsepatchioDisclosure
A critical 2FA bypass vulnerability (CVE-2026-40177) in ajenti.plugin.core has been disclosed, with administrators urged to review deployments and prepare for forthcoming patches; no proof of concept or active exploitation details are provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-40177 as an authentication bypass flaw affecting Ajenti Plugin Core versions earlier than 0.112, with no PoC, exploitation, or patch details provided.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑40177, noting a critical 2FA bypass in Ajenti that allows password skipping when MFA is enabled, without detailing PoCs, exploits, or fixes.