SSH SFTP server denial of service via extended channel data infinite loop. (CVE-2026-54886) Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl. (CVE-2026-54891) Plug: quadratic-time decoding of nested query/body parameters enables denial of service. (CVE-2026-54892) Email-derived URL path injection in the Swoosh Microsoft Graph adapter. (CVE-2026-54893)