CVE-2026-75329
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
Published 2026-08-26. Last modified 2026-08-31.