A critical vulnerability (CVE-2026-45695, CVSS 9.8) was disclosed affecting Kopia, the open-source backup and restore tool, allowing attackers to achieve unauthenticated remote code execution via SSH command-line argument injection. Due to the potential for full system compromise without any authentication, immediate patching is required. Technical Overview The issue originates from Kopia’s HTTP server API endpoint […] The post Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection appeared first on Orca Security .