Vulnerabilities
The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.
Hi, what are you looking for?
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.
The remote code execution flaw CVE-2026-3854 was found to impact GitHub.com and GitHub Enterprise Server.
A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System.
The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.
A code reuse issue enabled comma characters in certificate principals to be interpreted as list separators.
A race condition in PackageKit allows unprivileged users to escalate privileges when installing packages.
The vulnerability is tracked as CVE-2026-6770 and it has been patched with the release of Firefox 150 and Tor 15.0.10.
CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw.
Apple rolled out the security patches for dozens of iPhone and iPad models and generations.
The flaw allows attackers to access the SAM database, extract NTLM hashes, and gain System privileges.
All the flaws could have also been found by an elite human researcher, according to Mozilla.
Researchers discovered a remote code execution vulnerability and cybercriminals are using its reputation to deliver malware.
The company released 481 new security patches across 28 product families, including over 300 fixes for remotely exploitable, unauthenticated flaws.
Things are improving, but a researcher has still identified over 1,500 Perforce P4 instances allowing attackers to read files on the server.
The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before.
Forescout researchers discovered 20 new vulnerabilities in Lantronix and Silex products and described theoretical attack scenarios.
In-the-wild exploitation has been ongoing for a year, but no successful payload execution has been observed.
Other noteworthy stories that might have slipped under the radar: ShinyHunters targets Rockstar Games, ShowDoc vulnerability exploited in the wild, and EPA to boost...
The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.