CRITICAL 9.8 CVE-2026-86543 Published 7 Sept 2026

Tailscale Unauthenticated API Access

Worried this affects one of your servers?

The Tailscale management API is served without authentication by default in versions before 0.30.0, allowing attackers to access the /api/tunnel/start endpoint and provision a public tunnel.

This vulnerability affects fresh installations and does not require a password.

Reference: CVE-2026-86543 on NVD

← Back to Security News