NEOMSA APIM 4.6.0 Eliminates All Critical and High Vulnerabilities Registered in FSTEC BDU
Neoflex has released NEOMSA APIM 4.6.0, an on-premise API management platform and API Gateway. The main focus of this version is raising the security posture of the product supply chain.
Within the secure development lifecycle (SSDLC), engineers created an SBOM in CycloneDX format, scanned all components and transitive dependencies for known vulnerabilities using Grype, and mapped results to the FSTEC BDU database. After updating vulnerable libraries, the number of registered findings dropped from 57 to 7, with no Critical or High issues remaining in the final build.
Product overview
NEOMSA APIM includes an API Gateway, lifecycle management, authentication and authorization supporting OAuth 2.0, JWT and mTLS, rate limiting, traffic analytics, and a Developer Portal. It works with OpenAPI contracts and deploys on customer infrastructure, including Kubernetes, without sending traffic or metadata to the vendor cloud.
Release verification process
The security check follows a single pipeline:
- Build the release candidate with a frozen set of components.
- Generate the CycloneDX SBOM.
- Scan with Grype against CVE and GHSA databases.
- Map findings to the current FSTEC BDU export and assign severity, risk, and remediation status.
- Apply the Security Gate: the build is blocked until all Critical and High FSTEC BDU entries are resolved.
Medium and Low findings are recorded but do not block release; they are tracked for subsequent dependency updates.
Results
Updates eliminated all 10 Critical and 24 High vulnerabilities. Medium findings fell from 19 to 7, and all 4 Low findings were removed. The final 4.6.0 build contains no Critical or High entries from the FSTEC BDU at the time of the report.
Customers receive a controlled, auditable component list, a consolidated security report, and documented evidence that the product passed a formal security gate before shipment.
Related articles
Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence
Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.
Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper
Apache Struts has patched four vulnerabilities, one of which permits unauthenticated remote code execution through an OGNL injection flaw. The issue, tracked as CVE-2026-104711, only affects applications that still rely on the legacy RESTful mapper; modern configurations using the default mapper, restful2, or the official Struts REST plugin remain unaffected. Exploitation occurs when the legacy mapper extracts action names and parameters directly from the URL, allowing attackers to inject malicious OGNL expressions. Vulnerable releases span 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, and 7.0.0–7.3.0, with fixes available in 6.12.0 and 7.4.0. The remaining three flaws impact availability or cause cross-request data leakage but do not lead to code execution, and only one received an “important” severity rating.
Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery
The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.
Critical SSRF Vulnerability Affects SonicWall SMA1000 Series Remote Access Appliances
SonicWall has disclosed four vulnerabilities in its SMA1000 series remote access products, with one rated critical. The most severe issue, CVE-2026-102255, is a server-side request forgery flaw in the WorkPlace interface that allows unauthenticated attackers to abuse the appliance as a forward proxy and reach internal functions. The vulnerability received the maximum CVSSv3.0 base score of 10.0. Two additional flaws, CVE-2026-102256 and CVE-2026-102257, enable authenticated OS command injection and unauthenticated path traversal via crafted archives, respectively. No exploitation has been observed in the wild at the time of disclosure. SonicWall has released updates to address all issues.