Vulnerabilities

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related to authentication bypass, unauthorized workflow execution, server-side request forgery, stored cross-site…

5 hours ago

Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands

Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the…

7 hours ago

OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack

OpenSSH released version 10.6 on October 6, 2026, to address security vulnerabilities that affect encrypted sessions, file transfers, authentication, and…

1 day ago

Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception

Elastic published 14 security advisories addressing various vulnerabilities in Elasticsearch, Kibana, and Elastic Agent/Endpoint. Among these, a high-severity Kibana authorization…

1 day ago

Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code

Veeam released security updates to address a critical vulnerability that lets low-privileged users execute remote code on Veeam Backup Servers.…

1 day ago

Apache Struts Vulnerabilities Enable Remote Code Execution, DoS and Data Disclosure

Four Apache Struts vulnerabilities outlined in recent advisories expose affected applications to risks such as remote code execution, denial of…

2 days ago

IBM Patches Multiple Langflow OSS Flaws Including Two Critical RCE Vulnerabilities

IBM has disclosed 25 vulnerabilities in Langflow OSS, affecting versions 1.0.0 through 1.12.2. Two of these are critical flaws that…

2 days ago

Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory

A critical vulnerability exists in WatchGuard endpoint security products that could allow a local, authenticated attacker to bypass driver authentication…

2 days ago

Atlassian CVE-2026-21589 Flaw Exposes Files in Jira and Confluence Data Center

Atlassian has announced a critical vulnerability related to arbitrary file access that affects Jira Software Data Center and Confluence Data…

2 days ago

CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779, a high-severity vulnerability affecting Citrix NetScaler ADC and NetScaler…

3 days ago