Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
Tag: Vulnerability
New OVSwrap Linux Vulnerability Lets Attackers Gain Root Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-64531 and dubbed OVSwrap, allows unprivileged local users to escalate privileges to root…
Decades-Old BMC Vulnerability Exposes Data Centers
A critical security flaw affecting baseboard management controller (BMC) systems has left over 24,000 server management interfaces exposed to potential…
CISA Warns of Apache Tomcat Encryption Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known…
JADEPUFFER Agentic Ransomware Automates Database Extortion | CVE-2025-3248
Security researchers at the Sysdig Threat Research Team (TRT) have uncovered JADEPUFFER, the first documented case of an…
1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code
A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted…
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the…
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations.…
Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges
A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an…
Critical cPanel Flaw Lets Hosting Users Grab Database Root Access | CVE-2026-58048
A critical security vulnerability patched in cPanel could allow authenticated web hosting users to cross privilege boundaries and…
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply…
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a…
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and…
Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User
A critical privilege-escalation flaw in cPanel & WHM has been disclosed that could allow authenticated hosting users to execute arbitrary SQL commands…
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access.
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software…
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in…
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as…
Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild
Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud…