A critical vulnerability (CVE-2026-46354, CVSS 9.1) was disclosed affecting Coder, a popular open-source remote development platform, allowing attackers to steal workspace agent session tokens, Git SSH private keys, and OAuth credentials via a forged PKCS#7 signature bypass. Due to the unauthenticated nature of the attack and the breadth of potential secret exposure, immediate patching is […] The post Critical Coder Signature Bypass Exposes Developer Keys and Tokens appeared first on Orca Security .