Network Security
Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug.
Hi, what are you looking for?
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug.
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’.
The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.
The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product.
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling.
CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers.
A variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges.
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.
The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project.
The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.
The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities.
More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution.
CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.
The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven...
The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.
The security defects allow unauthenticated users to take control of the open source software supply chain.
The exploit timeline collapsed. Make sure your validation didn't.
Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June.