CRITICAL 9.8 CVE-2026-85663 Published 4 Sept 2026

Django Remote Code Execution Bug

Worried this affects one of your servers?

A critical vulnerability in Django 3.29.1 allows unauthenticated attackers to execute arbitrary code on the server.

Django, a popular web application framework, fails to authenticate requests and validates user input without an allowlist.

Attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

Reference: CVE-2026-85663 on NVD

← Back to Security News