TL;DR Attackers have begun CVE-2026-21589 exploitation against self-managed Atlassian servers. Researchers at watchTowr published a full technical...
Path Traversal
TL;DR Atlassian has patched CVE-2026-21589, a critical Atlassian Data Center vulnerability with a CVSS score of 9.3....
TL;DR On October 1, Dell fixed five flaws in Dell System Update (DSU), led by a 9.6...
TL;DR Attackers are exploiting CVE-2026-104286, a CVSS 9.8 FortiMail vulnerability that lets unauthenticated users write arbitrary files....
TL;DR Canonical has patched three critical LXD vulnerabilities rated CVSS 9.6 to 9.9. Each one lets a...
TL;DR WordPress 7.1.1 landed as a maintenance and security release. It fixes 11 security issues in the...
TL;DR TeamViewer has patched two TeamViewer vulnerabilities in its Desktop Clients. The more severe, CVE-2026-19042, is a...
TL;DR Apache InLong patched three flaws in version 2.4.0. The most notable is an Apache InLong SQL...
IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote...
TL;DR A critical W3 Total Cache vulnerability lets unauthenticated attackers write files anywhere on the server. Tracked...
TL;DR BigBlueButton contains a critical path traversal vulnerability within the Etherpad integration. Attackers can perform an unauthenticated...
TL;DR Gitea 1.27.1 patches a critical Gitea vulnerability, CVE-2026-59774, rated CVSS 9.8. An unauthenticated attacker can read...
TL;DR: The CodeIgniter4 team patched four security flaws in release v4.7.4. The most severe, a CodeIgniter4 RCE...
TL;DR IBM patched five IBM Aspera vulnerabilities across two products on July 20, 2026. They affect Aspera...
TL;DR ManageEngine patched a critical ADAudit Plus vulnerability tracked as CVE-2026-6516. Two weaknesses in the product’s Agent...
TL;DR Vitest patched a critical vulnerability rated CVSS 9.4. Browser Mode commands could read, write, or delete...
TL;DR Apache has patched a critical OpenMeetings vulnerability tracked as CVE-2026-49488. The path traversal flaw grants arbitrary...
TL;DR Notepad++ v8.9.7 fixes five security flaws in the popular Windows editor. Technical details and proof-of-concept exploit...
TL;DR PHP Composer, the main dependency manager for the language, patched three security flaws. The most serious,...
TL;DR A high-severity decompress npm vulnerability lets crafted archives write files outside the extraction folder. Tracked as...
TL;DR Apache IoTDB has patched three flaws in its time-series database. The worst is a critical path...
The Apache project patched three Apache Lucene.NET vulnerability issues in the 4.8.0-beta00018 release. Two of the flaws...