September 4, 2026
- A public exploit shipped for Cleo Harmony CVE-2026-84115, a JWT manipulation flaw giving authentication bypass and privilege escalation; fixed in 5.8.1.11 (SecurityWeek). Cleo MFT gear has a history of being an initial-access favourite (earlier coverage). · Exploitation & Vulnerabilities