<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Versa</title><description>Actively exploited vulnerabilities affecting Versa products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/versa.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-34026 — Versa Concerto Improper Authentication Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-34026</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-34026</guid><description>Versa Concerto, an SD-WAN orchestration platform, has a flaw in its Traefik reverse proxy configuration that lets unauthenticated attackers reach administrative endpoints. Once inside, attackers can access internal Actuator endpoints to pull heap dumps and trace logs, which can expose sensitive data including credentials or session tokens. Because SD-WAN orchestration platforms control wide network infrastructure, a compromise here could provide an attacker significant visibility into and control over enterprise network operations.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Versa</category><category>Concerto</category></item></channel></rss>