TL;DR A critical SQL injection flaw hits Weidmueller PROCON-WEB SCADA. Tracked as CVE-2026-16462, it scores a CVSS...
Vulnerability Report
TL;DR: A critical Rails Active Storage RCE flaw, CVE-2026-66066 (CVSS 9.5), lets an unauthenticated attacker read server...
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix...
TL;DR CERT/CC disclosed an Arris BGW210-700 vulnerability tracked as CVE-2026-16771. The authentication bypass affects firmware 2.7.7 and...
TL;DR OpenAM 16.1.2 patches four security flaws in the open-source access management server. Three of these OpenAM...
TL;DR The Erlang/OTP team fixed five security flaws across the runtime and its TLS stack. The most...
TL;DR: The CodeIgniter4 team patched four security flaws in release v4.7.4. The most severe, a CodeIgniter4 RCE...
TL;DR: Researchers at depthfirst released a working proof-of-concept for a GitLab RCE that runs commands as the...
TL;DR SolarWinds has patched a critical authentication bypass in SolarWinds Web Help Desk. Tracked as CVE-2026-28323, the...
TL;DR Adobe patched two critical flaws in Adobe Campaign Classic on July 29, 2026. The worst, CVE-2026-48449,...
TL;DR Attackers are hijacking internet-exposed MicroLogix 1400 controllers at U.S. water utilities. They change device IP addresses...
TL;DR The PHP project fixed three flaws in its latest releases. The headline bug is a PHP...
TL;DR A critical OpenRemote vulnerability, CVE-2026-66013, carries a CVSS score of 9.3. It lets an unauthenticated attacker...
TL;DR IBM disclosed four IBM WebSphere vulnerabilities in late July 2026. Two of them, CVE-2026-14512 and CVE-2026-14446,...
TL;DR MongoDB disclosed 27 vulnerabilities across MongoDB Server and the Compass GUI client. Most are denial-of-service bugs,...
TL;DR: A public proof-of-concept now targets CVE-2026-42530, an NGINX HTTP/3 RCE flaw rated CVSS 9.2. The use-after-free...
TL;DR: A public proof-of-concept now targets CVE-2026-66373, a Redis RCE flaw in the RESTORE command. The double-free...
TL;DR GitLab has shipped a new patch release for self-managed installs. Versions 19.2.1, 19.1.3, and 19.0.5 fix...
TL;DR Ruby on Rails has patched a critical Rails Active Storage flaw. Tracked as CVE-2026-66066 and rated...
TL;DR Google shipped a large Chrome security update on the Stable channel. It fixes 370 vulnerabilities, including...
TL;DR Cisco is warning about a Cisco FMC vulnerability under active attack. Tracked as CVE-2026-20316, it lets...
TL;DR Node.js shipped fixes for 11 vulnerabilities on 29 July 2026. Three are rated high severity, and...