Thursday, October 8, 2026

Vulnerabilities

HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands

HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that could allow unauthenticated...

Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests

OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions....

Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells

Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level access to vulnerable Application Delivery...

GitHub AI Agent Uncovers 24 Android App Vulnerabilities

GitHub Security Lab has disclosed 24 vulnerabilities in Android applications discovered through its open-source AI security agent and specialized audit taskflows. The findings highlight...

ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication

The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated attackers on a shared...

Citrix Confirms NetScaler Zero-Day RCE Flaws Actively Exploited in Attacks

Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772....

Apache Tomcat 11.0.26 Fixes 12 Security Flaws Enabling WebSocket Bypass and DoS Attacks

Apache Tomcat 11.0.26 has been released with fixes for 12 security vulnerabilities, including a significant flaw that could allow attackers to bypass security constraints...

HPE Networking Analytics Engine Flaws Let Attackers Gain Root Access

Hewlett Packard Enterprise (HPE) has announced security updates for its Networking Analytics and Location Engine (ALE), addressing 10 vulnerabilities that could lead to complete...