What happened
NVD published (2026-10-02) a four-CVE cluster for the HAVELSAN Sef AI Chatbot Platform, sourced from the Turkish national CERT (siberguvenlik.gov.tr) security notification TR-26-1241, covering SQL injection (CVSS 8.8), man-in-the-middle via improper certificate validation (7.4), missing authorization (5.3), and SSRF (4.9). The vendor was contacted and confirmed the product is not supported, meaning no patches will be shipped.
Why it matters
This is an AI chatbot platform shipped EOL with a full remote-attack surface (SQLi, SSRF, AiTM) and no remediation path. For any organization still running Sef, the only safe postures are isolation or migration; the SQLi and SSRF together could let an attacker reach backend data that the chatbot application proxies.
Attack vector
A set of four flaws disclosed via the Turkish national CERT bulletin TR-26-1241: SQL injection (CVE-2026-80298, CVSS 8.8); improper TLS certificate validation enabling adversarial-in-the-middle attacks (CVE-2026-80443); missing authorization letting users reach functionality not constrained by ACLs (CVE-2026-80337); and server-side request forgery (CVE-2026-80464)
Affected systems
HAVELSAN Inc. Sef AI Chatbot Platform before 2.1 (no longer supported by vendor)
Mitigation
No fixed release — the vendor stated the product is not supported. Immediately isolate or decommission exposed instances, place behind a WAF/reverse proxy, block outbound SSRF-prone requests, and disable TLS validation bypasses; plan migration off the EOL platform