What happened
NVD published a four-CVE cluster on 2026-10-02 for the HAVELSAN Sef AI Chatbot Platform (before 2.1): SQL injection (CVE-2026-80298, CVSS 8.8), certificate-validation AiTM weakness (CVE-2026-80443), missing authorization (CVE-2026-80337), and SSRF (CVE-2026-80464). The vendor states the product is not supported.
Why it matters
An EOL AI chatbot product with SQLi/SSRF/authz gaps is a live-risk flag for any org still running it; unsupported status means patching is impossible, so the action is decommission — Tier C due to narrow/niche blast radius but worth surfacing.
Attack vector
SQL injection into the chatbot backend; certificate-validation gaps enabling AiTM interception of chatbot traffic; missing ACL checks; and SSRF from the platform. All four published as a cluster by the Turkish national CERT (TR-26-1241) on 2026-10-02.
Affected systems
HAVELSAN Sef - AI Chatbot Platform < 2.1 (EOL / unsupported)
Mitigation
No fix available — product is end-of-life/unsupported; remediate by retiring the platform and not exposing it to untrusted networks.