search
CVE
Trends
- 1Guide released for AndroidX Security State 1.1.0โA practical guide to AndroidX Security State 1.1.0, device security patch visibility, pending updates, CVE verification,
A new practical guide covers AndroidX Security State 1.1.0, explaining how Android developers can check device security patch levels, surface pending updates to users, and verify CVEs. The walkthrough also covers building security-aware Android apps, with code examples in Kotlin using Jetpack libraries, and is being shared among developers in the Android and security engineering communities.
- 2Aon Ransomware Attack Linked to Termite Group Exploiting Cleo FlawโAon Ransomware Attack Analysis: Termite Group Exploits CVE-2024-50623 in Cleo Software
A newly published analysis attributes an attack on insurance broker Aon to the Termite ransomware group, which allegedly exploited CVE-2024-50623, a vulnerability in Cleo file-transfer software. The flaw, disclosed in late 2024, allowed remote code execution and was widely exploited by multiple ransomware crews. Security experts continue to urge organizations using Cleo products to patch immediately, warning that unpatched file-transfer platforms remain a prime target for extortion operations.
- 3Critical Atlassian flaw CVE-2026-21589 already under attackโ๐ค CVE-2026-21589 (CVSS 9.3): unauthenticated arbitrary file access in Atlassian Data Center products (Bitbucket, Conflue
Atlassian's Data Center products โ Bitbucket, Confluence and Jira โ are affected by CVE-2026-21589, a critical vulnerability (CVSS 9.3) allowing unauthenticated arbitrary file access. Security researchers report exploitation attempts began within two hours of public proof-of-concept details being released, making rapid patching urgent for organizations running affected software.
- 4Electric car catches fire at charging station in TurkeyโThis is not a very strong marketing message. # ev # ElectricVehicle # Turkeye Electric car bursts into flames at chargin
An electric vehicle caught fire at a charging station in Turkey, an incident captured on video and circulated widely online. The footage drew mocking reactions, with commenters joking that it was not a strong marketing message for electric vehicles. No injuries or details about the cause of the fire were reported in the initial coverage.
- 5Critical code injection flaw hits Movable Type Cloud EditionโCVE-2026-96408 (CRITICAL): Movable Type Cloud Edition (v2.0 โ 9.2.1) hit by code injection in upgrade script โ unauthent
A critical vulnerability, CVE-2026-96408, has been disclosed in Movable Type Cloud Edition versions 2.0 through 9.2.1. The flaw is a code injection in the upgrade script, allowing unauthenticated attackers to execute arbitrary Perl and SQL code. No patch is available yet, and administrators are being urged to restrict access to the upgrade script as an interim mitigation while a fix is awaited.
- 6Critical vulnerability disclosed in Eclipse ThreadX NetX DuoโCVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (โค6.5.1.202602). Exploitable pre-cert auth; ri
A critical out-of-bounds write vulnerability, tracked as CVE-2026-103416, affects Eclipse ThreadX NetX Duo versions up to 6.5.1.202602. The flaw can be exploited before certificate authentication and may allow remote code execution or denial of service. No patch is available yet, and security researchers are urging users to monitor vendor updates for embedded and IoT devices running the stack.
- 7Jaguar unveils Type 01 production electric GT with 1,016hpโJaguar Type 01 production version unveiled: 1,016hp electric GT, 720km range, 850V architecture # cars # electricvehicle
Jaguar has revealed the production version of its Type 01 electric grand tourer, billed with 1,016 horsepower, a 720km range and an 850-volt electrical architecture. The figures position the car as a flagship for Jaguar's all-electric relaunch under parent company Jaguar Land Rover, and the unveiling is drawing attention from car and EV enthusiasts worldwide.
- 8LibreOffice and OpenOffice Patch Critical Code Execution FlawsโLibreOffice and OpenOffice Patch Critical Remote Code Execution Vulnerabilities LibreOffice and Apache OpenOffice patche
The Document Foundation and Apache have released security updates for LibreOffice and OpenOffice fixing several critical vulnerabilities. Among them is CVE-2026-63277, a remote code execution flaw that lets attackers run malicious Java code through manipulated document files. Users are urged to install the patches promptly, as the flaw could allow full system compromise from simply opening a crafted file.
- 9Critical flaw in Manacle Technologies ERP system leaves users exposedโManacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets un
A critical vulnerability, CVE-2026-107104 with a CVSS score of 9.3, has been disclosed in Manacle Technologies' multi-tenant ERP system. Unsafe deserialization allows unauthenticated attackers to execute code remotely. No patch is available yet, so security researchers are urging users to restrict access and monitor affected systems until a fix is released.
- 10Flock becomes a CVE Numbering AuthorityโผFlock is now a CVE Numbering Authority assigning CVE IDs for Flock branded hardware and software products only. https://
Surveillance company Flock has been added to the CVE Program as a CVE Numbering Authority, meaning it can now assign official CVE identifiers to security vulnerabilities in its own Flock-branded hardware and software products. The designation, announced by the CVE Program, is drawing attention in the cybersecurity community given debate over Flock's surveillance footprint and how the company will handle disclosure of flaws in its own systems.
- 11Critical Atlassian flaw lets attackers read files unauthenticatedโ๐ค CVE-2026-21589 (critical): unauthenticated arbitrary file access in self-hosted Atlassian Data Center โ Jira, Confluen
Security researchers are flagging CVE-2026-21589, a critical vulnerability in self-hosted Atlassian Data Center products including Jira, Confluence, Bitbucket, Bamboo and Crowd. The flaw allows unauthenticated attackers to access arbitrary files, though they must know the exact file name or path since directory listing is not possible. Atlassian has released patched versions and reports no known exploitation so far. Administrators are urged to update their deployments promptly.
- 12wolfSSH flaw CVE-2026-16516 flagged over data authenticityโwolfSSH https:// radar.offseq.com/threat/cve-20 26-16516-cwe-345-insufficient-verification-of-data-authenticity-in-wolfs
A new vulnerability, CVE-2026-16516, has been catalogued in wolfSSH, the SSH library from wolfSSL Inc. The flaw is classified as CWE-345, insufficient verification of data authenticity, meaning the library may accept data without properly confirming it comes from a trusted source. The listing is circulating among security researchers, who are tracking it as a potential concern for products embedding wolfSSH.
- 13ShinyHunters exploited unpatched Oracle PeopleSoft flaw, FBI analysis findsโผFBI Data Breach Analysis: ShinyHunters Exploit Unpatched Oracle PeopleSoft CVE-2026-35273 Due to Third-Party Patch Failure
An FBI breach analysis indicates the hacking group ShinyHunters exploited CVE-2026-35273, a vulnerability in Oracle PeopleSoft, which remained unpatched at affected organisations because of a failure in third-party patching processes. Security coverage of the finding is focused on the supply-chain lesson: even when vendors issue fixes, gaps in third-party patch management can leave enterprises exposed to data theft.
- 14Citrix and Fortinet zero-days under active exploitationโRecent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-10428
Security researchers warn that newly disclosed zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) are being actively exploited, with critical infrastructure and government organisations among the targets. Apple has separately patched a CoreGraphics flaw already used in attacks. Administrators are urged to apply patches urgently and review systems for signs of compromise.
- 15Critical vulnerability disclosed in Payload CMSโผ๐ด CVE-2026-105859 - Critical (9.8) Payload is a free and open source headless content management system. In versions bef
A critical vulnerability, CVE-2026-105859 with a severity score of 9.8, has been disclosed in Payload, a free and open source headless content management system. Versions before 3.90.0 and canary versions before 4.0.0-canary.34 are affected: an attacker can submit a request to a specific update endpoint that modifies collection documents. Security teams using Payload are being urged to update to patched versions immediately.
- 16Critical file-access flaw hits self-hosted Atlassian productsโ๐ค CVE-2026-21589: critical arbitrary file-access flaw in self-hosted Atlassian Data Center products (Confluence, Jira, B
Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability affecting self-hosted Data Center versions of Confluence, Jira and Bitbucket. The flaw could let attackers read sensitive files on affected servers. Atlassian is urging administrators to patch immediately. Security commentators are sharing the advisory and warning self-hosted deployments to act quickly.
- 17Critical CVE in GitLab's AI Gateway Sparks Security ReviewโEarlier this month, a critical vulnerability showed up in GitLab's AI Gateway โ CVE-2026-90970, CVSS... # ai # security
A critical vulnerability, CVE-2026-90970, was discovered earlier this month in GitLab's AI Gateway, drawing attention to how AI agent permissions are handled in developer tools. The flaw, rated with a high CVSS severity score, has prompted security-minded developers to re-examine their own systems and question whether permission models for AI agents are properly isolated from core infrastructure.
- 18Critical flaw in Dell Container Storage Modules disclosedโ๐ด CVE-2026-61421 - Critical (9.8) Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-co
A critical vulnerability, CVE-2026-61421 with a severity score of 9.8, has been disclosed in Dell Container Storage Modules versions prior to 1.18.0. The flaw involves hard-coded credentials in the CSM Authorization component, meaning an unauthenticated attacker with remote access could potentially exploit it. Users are being urged to update to version 1.18.0 or later.