Thursday, October 8, 2026

CVE/vulnerability

Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks

Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw, tracked as CVE-2026-88779,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain...

Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking

cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or execute...

Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android and iOS applications, posing as the...

Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers

Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances. This flaw, tracked as CVE-2026-104286,...

Apache HTTP Server Flaws Enable Remote Code Execution and Denial-of-Service Attacks

Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server 2.4. These vulnerabilities include...

Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content

A critical vulnerability in Next.js could let unauthenticated remote attackers execute code on affected servers by supplying crafted input that gets rendered into SVG...

Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks

Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side applications, potentially enabling server-side...