Version vulnerabilities
VAPT Hybrid Agent 2.6.0 through 2.8.3
Public VAPT disclosures for VAPT Hybrid Agent 2.6-2.8 VAPT Hybrid Agent 2.6.0 through 2.8.3, with direct links back into the canonical CVE and case records.
9.8 Critical
Latest disclosure Mar 11, 2026
Disclosure filters
Inspect the public records behind this version.
Public vulnerabilities
VAPT · Hybrid Agent 2.6-2.8 · VAPT Hybrid Agent 2.6.0 through 2.8.3
1 public VAPT records in the current version view.
Agent enrollment token reuse in hybrid automation fleet
A provisioning flaw allowed previously issued enrollment tokens to be replayed during bootstrap, leading to unauthorized agent registration in specific hybrid deployments.
CRITICAL
96.0%
Mar 11, 2026