Amazon AWS
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration.
These vulnerabilities could allow unauthenticated administrative takeover,...
Cyber Security News
CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities (KEV) Catalog...
CVE/vulnerability
Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain...
CVE/vulnerability
Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or execute...
CVE/vulnerability
Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances.
This flaw, tracked as CVE-2026-104286,...
CVE/vulnerability
Apache HTTP Server Flaws Enable Remote Code Execution and Denial-of-Service Attacks
Apache HTTP Server administrators are urged to apply security updates following the disclosure of multiple vulnerabilities affecting Apache HTTP Server 2.4.
These vulnerabilities include...
CVE/vulnerability
Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks
Axios maintainers have disclosed several high-severity security vulnerabilities that could allow attackers to bypass proxy and DNS controls in server-side applications, potentially enabling server-side...
CVE/vulnerability
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related services.
These vulnerabilities affect...