CVE/vulnerability

We talk about the newest information and stories about Common Vulnerabilities and Exposures (CVE) and security holes in this section. This includes newly found security holes, security patches, warnings, and the best ways to fix them. Know about the newest dangers and how to keep your data and systems safe from possible security risks.

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users' session…

2 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process deployments by exploiting unsafe Python…

3 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw that could allow a man-in-the-middle…

4 hours ago

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site…

5 hours ago

Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root

Cisco has disclosed three critical vulnerabilities in its Nexus 3000 and 9000 Series switches that could allow unauthenticated remote attackers…

5 hours ago

PoC Exploit Released for Critical VMware Vulnerability Enabling Guest-to-Host Attacks

A public proof-of-concept (PoC) exploit has been released for CVE-2026-59346, a critical integer overflow flaw in VMware Workstation and Fusion…

5 hours ago

Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands

Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the…

6 hours ago

Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI…

1 day ago

OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack

OpenSSH released version 10.6 on October 6, 2026, to address security vulnerabilities that affect encrypted sessions, file transfers, authentication, and…

1 day ago

Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception

Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a high-severity Kibana authorization…

1 day ago