Vulnerabilities

MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components

MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted…

3 days ago

AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft

AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could…

3 days ago

CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known…

3 days ago

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote…

6 days ago

Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking

cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM…

6 days ago

Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers

Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances. This…

6 days ago

Apache HTTP Server Flaws Enable Remote Code Execution and Denial-of-Service Attacks

Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server…

6 days ago

Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks

Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side…

1 week ago

Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation

TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related…

1 week ago

HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws…

1 week ago