CVE-2026-67598: Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to config...
Added to the CISA Known Exploited Vulnerabilities catalog on 03 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.4.
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_S...
Required action: Review and patch if applicable to your AI infrastructure.