TL;DR Siemens has patched a maximum-severity Opcenter X authentication bypass, tracked as CVE-2026-56451. The flaw scores 10.0...
JWT
TL;DR A researcher disclosed a Kafka authentication bypass in the OAUTHBEARER login path. It affects Apache Kafka...
TL;DR Apache APISIX 3.16.0 shipped a JWT algorithm confusion bug in its jwt-auth plugin. The flaw, tracked...
Security researchers have disclosed two major vulnerabilities within fast-jwt, a high-performance library used to implement JSON Web...
The OpenBao community, the open-source initiative dedicated to managing and distributing sensitive data like secrets and certificates,...
A widely used Python library implementing JOSE standards, joserfc, has disclosed a critical uncontrolled resource consumption vulnerability—tracked...
Moxa, a leading manufacturer of industrial networking and security appliances, has released an urgent security advisory addressing...
The Formbricks project, an open-source platform for building in-app and website surveys, has released an urgent patch...
A coordinated disclosure by CERT@VDE and WAGO has unveiled a devastating vulnerability—CVE-2025-41672—impacting WAGO’s industrial automation platform Device...
A critical vulnerability—CVE-2025-20188—has been disclosed in Cisco IOS XE Wireless LAN Controller (WLC) software, allowing unauthenticated attackers...