TL;DR Researchers disclosed three pre-authentication flaws in Xlight FTP Server. The most severe is a Xlight FTP...
Vulnerability Report
TL;DR HashiCorp patched three bugs in its Terraform MCP Server. The worst Terraform MCP Server flaw, CVE-2026-16498,...
TL;DR The Apache Software Foundation fixed 38 Apache Traffic Server vulnerabilities. The patches landed in versions 9.2.15...
TL;DR Researchers at Calif.io published full technical details and working proof-of-concept exploit code for CVE-2026-50343, tracked as...
TL;DR A new Linux kernel vulnerability, tracked as CVE-2026-53264, lets a local user run arbitrary code and...
TL;DR A researcher has published full details and a working proof-of-concept for a macOS privilege escalation bug....
TL;DR Gitea 1.27.1 patches a critical Gitea vulnerability, CVE-2026-59774, rated CVSS 9.8. An unauthenticated attacker can read...
TL;DR Veeam patched four flaws in Veeam Service Provider Console. Two are critical. One is an unauthenticated...
TL;DR Adobe published a Priority 1 security update for Adobe Campaign Classic. The patch resolves seven severe...
TL;DR Four new Apache NiFi vulnerabilities affect installations running versions prior to 2.11.0. These flaws allow attackers...
TL;DR: cPanel patched a cPanel root SQL execution flaw tracked as CVE-2026-58048, rated CVSS 9.4. A second,...
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR: Check Point patched a Check Point authentication bypass affecting its Security Management and Multi-Domain Security Management...
TL;DR Researchers at LAVA found 36,872 exposed BMCs on the public internet. Most leaked password-derived hashes before...
TL;DR SICK InspectorP6xx machine-vision sensors have a critical remote-access flaw. Tracked as CVE-2026-11841, it scores a CVSS...
TL;DR Apple has patched a macOS privilege escalation flaw tracked as CVE-2026-39875. A malicious app can chain...
A ColdCard wallet hack has devastated countless Bitcoin investors. Hackers exploited a severe firmware vulnerability to drain...
TL;DR TP-Link patched a serious TP-Link TL-WR940N flaw, CVE-2026-12935. The bug allows unauthenticated remote code execution on...
TL;DR A critical SQL injection flaw hits Weidmueller PROCON-WEB SCADA. Tracked as CVE-2026-16462, it scores a CVSS...
TL;DR: A critical Rails Active Storage RCE flaw, CVE-2026-66066 (CVSS 9.5), lets an unauthenticated attacker read server...
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix...
TL;DR CERT/CC disclosed an Arris BGW210-700 vulnerability tracked as CVE-2026-16771. The authentication bypass affects firmware 2.7.7 and...