CVE-2026-16647: Zyxware Disable Login Page

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

Affected products

  • Zyxware Disable Login Page: before 1.1.4 (fixed in 1.1.4)

Published 2026-09-02. Last modified 2026-09-08.