Latest coverage
- Community aggregator
- Country: United States
Field Value CVE ID CVE-2026-6951 Affected package simple-git (npm) Affected versions < 3.36.0 Patched version 3.36.0 CWE CWE-94 (Improper Control of Generation of Code), CWE-88 (Argument Injection) CVSS 3.1 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Disclosed 2026-04-25 1. Overview…
- Community aggregator
- Country: United States
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: two edge RCE flaws attacked before a fix existed Citrix published fixes for two NetScaler flaws on 2026-09-27 after watchTowr reported unpatched remote code execution bugs under active exploitation. Both flaws are rated 9.5 under CVSS v4. The two…
- Trade press
- Country: United States
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
- Community aggregator
- Country: United States
If you use Legcord as your Discord client, a script running in the Discord page can break out of the Electron sandbox entirely. CVE-2026-105293 (CVSS 8.1) — Path Traversal to RCE Theme IPC handlers (themes.install, themes.uninstall, themes.folder) accept identifiers without sanitizing ../…
- Trade press
- Country: United States
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG)…
- Community aggregator
- Country: United States
Microsoft's September Patch Tuesday landed a record-setting pile of roughly 970 new CVEs, and two of them are already being exploited. Buried in that pile is the one I would patch first: CVE-2026-69730, a CVSS 9.8 remote code execution in the Windows DNS Server role. No authentication, no user…
- Community aggregator
- Country: United States
Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind Three remote code execution identifiers in one month is an unusual run for any infrastructure component, and the Redis sequence during August 2026 reads better as one story than as three separate advisories.…
- Trade press
- Country: United States
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
- Trade press
- Country: United States
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is…