The Access Group published a security advisory for CVE-2026-86253 for h3 on September 6, noting that percent-encoded traversal sequences reaching serveStatic() can allow unauthenticated arbitrary file reads on affected Node.js deployments.
Public source
Publisher name
Public post
The Daily Product Security Brief (07 Sep 2026) Today’s product security signal: critical unauthenticated attack paths and authorization failures dominate a quiet Sunday-…
Company
The Access Group
- Industry
- Software Development
- Location
- Loughborough, GB
- Company size
- 5,001–10,000 employees
About The Access Group
The Access Group is one of the largest UK-headquartered business management software providers. It provides solutions that empower more than 160,000 small and mid-sized organisations in commercial and non-profit sectors across Europe, USA and APAC, giving every employee the freedom to do more of what’s important. Its innovative cloud solutions and integrated AI software experience across multiple Access products transform how business technology is used. Access employs over 8,500 people, continuously driving product innovation and customer service excellence.
See moreLatest activity
Latest activity from The Access Group
29 signals
Presence & Recognition
The Access Group employee Adam King was shortlisted for Learning Developer of the Year at the Learning Technologies Awards 2026.
Products & Services
The Access Group reported that Adobe's September 8 Photoshop update fixes multiple critical arbitrary-code-execution flaws and a security-feature bypass.
Products & Services
The Access Group built the Access transport solution within Access Evo to connect home-to-school transport to children's services data and make faster, better-informed decisions about routes, providers, and eligibility.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
NodeSource
NodeSource released a low-severity security fix for undici in versions 6.28.1, 7.29.1, and 8.10.2 to address CVE-2026-18540 vulnerability via downstream response splitting.
Products & Services
Factory Internet
Factory Internet published a security advisory for SonicWall SMA1000 appliances with vulnerabilities CVE-2026-83548 and CVE-2026-83549, which can be chained to achieve unauthenticated remote code execution.
Products & Services
Resecurity
Resecurity is tracking active exploitation of CVE-2026-81578, a vulnerability related to missing authentication and authorization boundary issues affecting the web management interface of PaperCut NG and PaperCut MF.
Products & Services
Beazley Security
Beazley Security released a new advisory on two critical vulnerabilities, CVE-2026-83548 and CVE-2026-83549.
Products & Services
Graylog, Inc.