CVE-2026-16504: Vps.org Zulip Template

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Affected products

  • Vps.org Zulip Template: affected versions not specified

Published 2026-07-31. Last modified 2026-09-08.