Vulnerabilities
Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster.
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations.
Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation.
Proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems.
Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure.
The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.
The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests...
The browser update resolves critical-severity security defects that could potentially lead to remote code execution.
Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging...
Project Lightwell is designed to fix vulnerabilities without breaking what is already in production.
The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure.
Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx.
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.
Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites.
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges.