CVE-2026-90481
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
- Published Sep 24, 2026
- CVSS 9.2 critical
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available