Thursday, October 8, 2026

CVE/vulnerability

Apache Struts Vulnerabilities Enable Remote Code Execution, DoS and Data Disclosure

Four Apache Struts vulnerabilities outlined in recent advisories expose affected applications to risks such as remote code execution, denial of service, and cross-user data...

IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities

IBM has disclosed 25 vulnerabilities in Langflow OSS, affecting versions 1.0.0 through 1.12.2. Two of these are critical flaws that allow unauthenticated remote code...

Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory

A critical vulnerability exists in WatchGuard endpoint security products that could allow a local, authenticated attacker to bypass driver authentication and access sensitive kernel...

Atlassian CVE-2026-21589 Flaw Exposes Files in Jira and Confluence Data Center

Atlassian has announced a critical vulnerability related to arbitrary file access that affects Jira Software Data Center and Confluence Data Center. This vulnerability, tracked...

CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779, a high-severity vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its...

MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components

MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted execution, and system components...

AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft

AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow unauthenticated administrative takeover,...

Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940

Microsoft has released a revised security update package for on-premises Exchange Server, dated September 2026, which includes a fix for CVE-2026-96940. This V2 release...