← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJan 15, 2026 · 14:18via API Security News

Issue 287: Critical RCEs in n8n, HPE OneView, SmarterMail, and an Authentication Bypass in IBM API Connect

Brief

Welcome to this first edition of the APIsecurity newsletter for 2026, I’m Philippe Leothaud, CTO and co-founder of 42Crunch, and your new Newsletter Editor. I’d like to thank Anthony Lonergan for the excellent work he’s done over the years building this newsletter into a trusted source for API security news and insights.

I’ll continue that tradition — with a strong focus on real-world API incidents, design-time protections, and the growing impact of automation and AI on API ecosystems.

Below are the most significant API-relevant security stories from the last few weeks — from critical RCEs to gateway authentication bypasses and automation-platform exploits and an excellent article on BOLA.

Read more on API Security News