Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
Hi, what are you looking for?
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
The browser update resolves several critical-severity memory safety and memory corruption flaws.
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts.
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug...
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.