TL;DR Threat actors are now actively targeting a critical SonicWall SMA1000 vulnerability in the wild. The flaw...
ssrf
TL;DR Cisco has disclosed CVE-2026-20362, an unauthenticated server-side request forgery (SSRF) flaw in Finesse rated 7.2 on...
TL;DR Gitea has shipped 27 security fixes across versions 28.0.0 and 28.1.0. This Gitea security update closes...
TL;DR SonicWall has fixed four flaws in its SMA1000 remote access appliances, led by CVE-2026-102255, a SonicWall...
TL;DR Kiteworks disclosed 78 security flaws across its Core platform, Email Protection Gateway, and forms products. Nine...
IBM X-Force has disclosed two security vulnerabilities in Langflow OSS, including a severe Langflow SSRF flaw. The...
A critical ONLYOFFICE ownCloud plugin SSRF vulnerability allows authenticated administrators to force arbitrary network requests. This flaw...
Roundcube shipped a security update on September 6, 2026. The Roundcube security update patches 12 vulnerabilities across...
ASUS published CVE-2026-75754 on September 4, 2026. This ASUS Control Center vulnerability earns a maximum CVSS score...
TL;DR Apache InLong patched three flaws in version 2.4.0. The most notable is an Apache InLong SQL...
TL;DR A default MLflow tracking server can be turned into a proxy for reading internal services. Tracked...
Roundcube shipped two security updates this week. Also, versions 1.6.18 and 1.7.3 close eleven separate bugs. The...
TL;DR Progress released an August 2026 bulletin for MarkLogic Server. It fixes ten MarkLogic Server vulnerabilities, several...
Autonomous Agents Exchange Covert Intelligence Under standard testing protocols, human engineering teams deployed and evaluated distinct AI...
TL;DR A researcher found six SGLang vulnerabilities, and the worst allow unauthenticated remote code execution. SGLang serves...
TL;DR The Django team shipped security releases 6.0.8 and 5.2.17 on August 4, 2026. They fix four...
TL;DR Adobe published a Priority 1 security update for Adobe Campaign Classic. The patch resolves seven severe...
TL;DR IBM disclosed four IBM WebSphere vulnerabilities in late July 2026. Two of them, CVE-2026-14512 and CVE-2026-14446,...
TL;DR OpenDJ 5.1.2 fixes four security flaws in the open-source LDAP directory server. The two most severe...
TL;DR: Arista confirmed that CVE-2026-16812, a VeloCloud command injection flaw, is under active attack. The bug scores...
TL;DR Zimbra released Collaboration Suite 10.1.20 on July 20, 2026. The update fixes several Zimbra vulnerabilities, including...
TL;DR Red Hat has flagged a critical flaw in Red Hat OpenShift AI. Tracked as CVE-2026-15378, it...