payloadforge
@payloadforge@infosec.exchange
infosec.exchange
I wrote up CVE-2026-56877, a Skillable SCORM launch issue where the browser supplied userId drove lab allocation while the token was the only trusted value. Skillable's answer was migration, no SCORM path fix, and a private customer advisory. That is why the public record matters for anyone doing vendor due diligence.
https://payloadforge.io/beyond-crto-skillable
#SCORM #Disclosure #ThirdPartyRisk