
🚨 ANOTHER AI SECURITY TOOL HAS TWO NEW VULNERABILITIES — THIS TIME HEXSTRIKE AI CVE-2026-90619 + CVE-2026-90620 CyberSignal Priority: 🟠 HIGH HexStrike AI is designed around AI-assisted offensive-security workflows. Today, two vulnerabilities were published affecting the tool itself. CVE-2026-90619 OS command injection affecting the Execute Endpoint in: hexstrike_server.py Public vulnerability information says the issue can be attacked remotely and exploit information is publicly available. CVE-2026-90620 Missing authentication affecting an API command endpoint. Again: remote exploitation is described as possible. That's an uncomfortable combination. NO AUTHENTICATION + COMMAND-EXECUTION SURFACE + OFFENSIVE SECURITY AUTOMATION The project was reportedly notified, while the public vulnerability records indicate that rolling releases make conventional affected-version boundaries difficult to specify. 🧠 CyberSignal insight AI security tooling deserves the SAME threat modeling as the systems it attacks. Giving an autonomous offensive-security framework shell access while exposing insufficiently protected control endpoints creates an extremely powerful trust boundary. Secure the hacker's AI too. Sources: CVE-2026-90619 · CVE-2026-90620 Published: September 14, 2026
