TL;DR Two new FreePBX vulnerabilities each carry a CVSS score of 9.3. One gives unauthenticated remote code...
Vulnerability Report
TL;DR Oracle patched 11 flaws in the WebLogic Server Core component this July. Most allow a full...
An Unprecedented Autonomous Intrusion The prominent open-source model and dataset repository Hugging Face disclosed a sophisticated cyberattack...
TL;DR Google shipped a Chrome security update on July 21, 2026. It fixes 12 vulnerabilities, and Google...
TL;DR Vitest patched a critical vulnerability rated CVSS 9.4. Browser Mode commands could read, write, or delete...
TL;DR SolarWinds fixed 15 critical SolarWinds Serv-U vulnerabilities on July 21, 2026. They allow privilege escalation, account...
TL;DR Qualys found a snap-confine privilege escalation flaw, tracked as CVE-2026-8933. It lets any local user reach...
TL;DR CISA added four flaws to its KEV catalog on July 21, 2026. The list covers critical...
TL;DR ASUS has published five security advisories covering seven vulnerabilities. They span router firmware, MyASUS driver components,...
TL;DR A public proof-of-concept now targets CVE-2026-42980, a Windows privilege escalation flaw in the NT kernel. The...
TL;DR Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache...
TL;DR Zimbra released Collaboration Suite 10.1.20 on July 20, 2026. The update fixes several Zimbra vulnerabilities, including...
TL;DR CVE-2026-50522 is a critical SharePoint RCE flaw rated CVSS 9.8. Researchers report active exploitation attempts, and...
TL;DR Apache has patched a critical OpenMeetings vulnerability tracked as CVE-2026-49488. The path traversal flaw grants arbitrary...
European cloud provider OVH just published a candid retrospective on its emergency patch campaign. The post explains...
Attackers are already dropping webshells on WordPress sites through a flaw in WordPress Core itself. The bug...
TL;DR A critical Gitea vulnerability, CVE-2026-58443 (CVSS 9.6), lets a public-only token push commits into a private...
TL;DR The Apache Doris project has patched a critical Apache Doris vulnerability, tracked as CVE-2026-58319. Some Frontend...
TL;DR Siemens has patched a maximum-severity Opcenter X authentication bypass, tracked as CVE-2026-56451. The flaw scores 10.0...
TL;DR A critical Kimai vulnerability, CVE-2026-52824 (CVSS 9.1), affects the open-source time-tracking app’s official Docker image. The...
TL;DR The Okta Red Team recently found a severe crash flaw in a core secure library. A...
TL;DR A critical flaw in the ServiceNow AI platform allows unauthenticated users to run arbitrary commands. DefusedCyber...