Two high-severity vulnerabilities were disclosed affecting widely used infrastructure software. GoHarbor Harbor is affected by CVE-2026-4404, a hard-coded/default credential issue in version 2.15.0 and below that can let attackers authenticate to the Harbor web UI with the default administrator password if it was never changed. The published scoring indicates the flaw is network-accessible, requires no privileges or user interaction, and can lead to high confidentiality and integrity impact.
N2WS Backup & Recovery is affected by CVE-2025-32991, which impacts versions before 4.4.0 and can lead to remote code execution through a two-step attack against the product’s RESTful API. The CVSS v3.1 vector rates the issue as remotely exploitable with no required privileges or user interaction, despite high attack complexity, and assigns high impact across confidentiality, integrity, and availability. The CVE entry was updated with links to an N2WS security advisory and vendor resources.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE-2025-32991 record was updated to add a CVSS v3.1 vector, classify the issue as CWE-362, and include references to an N2WS security advisory update and the N2WS website.
A CVE entry for CVE-2025-32991 was received for N2WS Backup & Recovery versions before 4.4.0, describing a two-step attack against the product's RESTful API that can result in remote code execution.
Later the same day, the CVE-2026-4404 record was modified to add CVSS v3.1 scoring and CWE mappings, characterizing the flaw as network-accessible, low complexity, and requiring no privileges or user interaction.
A new CVE, CVE-2026-4404, was published for GoHarbor Harbor 2.15.0 and earlier, describing a hard-coded/default credential weakness that allows authentication to the Harbor web UI if the default administrator password was not changed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.