All verified exploits

CVE-2026-4404 Default Admin Credentials

Deterministic critical Harbor Added cve-verified-cve-2026-4404

Detects Harbor container registry instances running version 2.15.0 or earlier where the default admin password (Harbor12345) has not been changed. Attackers can authenticate with these well-known credentials to gain full admin access — pulling private images, pushing malicious ones, and compromising container supply chains.

Is your app exploitable through CVE-2026-4404?

Scan your domain free