TL;DR Apache APISIX 3.16.0 shipped a JWT algorithm confusion bug in its jwt-auth plugin. The flaw, tracked...
Authentication Bypass
TL;DR Signal 11 disclosed a NetComm authentication bypass tracked as CVE-2026-35019. The flaw scores 9.2 on CVSS...
TL;DR JetBrains fixed three security flaws across Hub, YouTrack, and GoLand. The worst is a JetBrains authentication...
TL;DR The Apache Tomcat project disclosed seven vulnerabilities on 29 June 2026. The most serious Apache Tomcat...
TL;DR WSO2 patched seven vulnerabilities across its API platform, including WSO2 API Manager, in June 2026. The...
On 29 June 2026, CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog. The flaw is a...
TL;DR The Python Software Foundation fixed a python.org authentication bypass on February 24, 2026. The flaw sat...
TL;DR IBM disclosed two critical flaws in Langflow OSS, the open-source AI workflow builder. One is a...
Two critical Gitea security flaws currently threaten self-hosted development environments. These severe vulnerabilities allow remote attackers to...
TL;DR Webmin released version 2.641 to fix three Webmin vulnerabilities. The most serious one lets an unauthenticated...
A one-line bug that survived 27 years Researchers at Argus have publicly disclosed an OpenBSD authentication bypass...
Critical bug exposes LiteLLM management routes A newly disclosed LiteLLM authentication bypass could let unauthenticated attackers...
Rockwell Automation has disclosed two security advisories that reveal several Rockwell Automation vulnerabilities across its industrial product...
A critical Apache Shiro LDAP Injection vulnerability has recently emerged. Specifically, security researchers identified a severe...
A critical Cloud Foundry UAA vulnerability has emerged, and it lets attackers slip past SAML logins entirely....
A critical phpBB authentication bypass is putting countless online communities at risk right now. The flaw, tracked...
Recently, a maximum-severity flaw emerged in the remote management software landscape. Cybersecurity researchers found a critical SimpleHelp...
Cybersecurity experts recently identified a massive threat to WordPress websites. Specifically, hackers are actively exploiting a critical...
Critical Security Vulnerabilities Threaten Enterprise Gateways The development team at Ivanti released urgent software maintenance updates for...
Multiple Flaws Threaten Enterprise Java Deployments Across Clusters The enterprise development team managing the Java cloud ecosystem...
Critical Authentication Bypass Threatens Remote Access Deployments A serious security warning has been issued for corporate virtual...
Enterprise infrastructure administrators face an immediate deployment challenge. Specifically, multiple IBM WebSphere execution flaws threaten to compromise...