CVE-2026-90999: Functional Software, Inc Sentry Seer
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the victim’s Sentry account, source repository, or infrastructure.
Affected products
- Functional Software, Inc Sentry Seer
Published 2026-09-16. Last modified 2026-09-18.