// SlackHIGH
CVE-2026-61699 is a high-severity vulnerability (CVSS 8.1) in nebula-mesh, Slack's self-hosted mesh VPN control plane. Prior to version 0.7.1, the blocklist mechanism fails to reach peer configurations, allowing attackers who exfiltrate host credentials to maintain full network overlay access for 30–365 days after revocation. Operator-visible state (UI and audit logs) does not accurately reflect the compromised host's actual connectivity status. Update to version 0.7.1 or later to remediate.
// Get alerts for Slack