MikeTrendsTrends right now

search

CVE

Trends

  1. 1
    EU Reporting Rules Put Linux Vulnerability Management Under Pressure●The # EU Is About to Make # Linux 's # Vulnerability Management Problem Harder to Ignore More # CVE , sprawling deploymeMmastodonWorldEU Politics211 h ago

    The EU's upcoming cybersecurity reporting requirements are set to expose long-standing weaknesses in how Linux vulnerabilities are tracked and patched. The number of published CVEs has grown sharply, and sprawling deployments make it harder for organisations to prove which systems are affected. Under the new rules, patching alone may not suffice: teams will need documented evidence of their vulnerability handling, turning compliance into a pressing operational challenge for Linux users across Europe.

  2. 2
    Critical flaw in Apache OpenOffice lets documents run codeβ–ΌCVE-2026-59265: A critical flaw in Apache OpenOffice's Java integration lets a crafted untrusted document execute arbitrMmastodonTechnologyCybersecurity29 h ago

    A critical vulnerability, tracked as CVE-2026-59265, has been found in Apache OpenOffice's Java integration. Opening a crafted untrusted document can allow arbitrary code execution on the affected machine. Versions 4.1.16 and earlier are affected, and no exploitation has been confirmed so far. A fix is expected in version 4.1.17; users are advised to disable the Java runtime as an interim measure.

  3. 3
    GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityβ—πŸš¨ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI GatMmastodonTechnologyCybersecurity11 h ago

    GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.

  4. 4
    GitLab Rushes Emergency Fixes for Exploited AI Gateway Flaws●GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws GitLab released emerMmastodonTechnologyCybersecurity23 h ago

    GitLab has released emergency security patches addressing two critical vulnerabilities: a remote code execution flaw in its AI Gateway, tracked as CVE-2026-90970, and a maximum-severity path traversal issue. Both flaws are reportedly being actively exploited, prompting the unusually urgent rollout. Security teams are being urged to apply the updates immediately, with the disclosures fueling renewed discussion about securing AI infrastructure.

  5. 5
    YesWiki hit by nine vulnerabilities including SQL injection flawβ—πŸš¨ YesWiki 9 CVEs β€” CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requirMmastodonTechnologyCybersecurity11 h ago

    Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.

  6. 6
    Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3●Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a paMmastodonTechnologyMobile21 d ago

    A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.

  7. 7
    Critical vulnerability found in NASA's AIT-Core software●NASA-AMMOS AIT-Core ≀3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry toMmastodonTechnologyCybersecurity11 h ago

    NASA's AMMOS AIT-Core toolkit, used for spacecraft ground systems, has a critical vulnerability tracked as CVE-2026-105105. The flaw affects versions up to 3.1.1: its ZeroMQ bus ships without authentication, potentially exposing spacecraft commands and telemetry to remote attackers. NASA has released version 3.1.2, which restricts bus access to the local loopback interface, and users are urged to upgrade immediately.

  8. 8
    SourceHut account takeover flaw found in build log rendering●SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 https:// reddthat.com/post/74210240MmastodonTechnology220 h ago

    A security vulnerability in SourceHut, tracked as CVE-2026-92973, reportedly allowed account takeover through malicious build logs. The flaw involved cross-site scripting in the ansi2html.py script used to render logs, letting attackers inject code that could hijack sessions. Developers and security researchers are discussing the disclosure and how the issue was handled.

  9. 9
    Critical CVE-2026-71885 flagged in Bouncy Castle BC-Java●CRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA ( https:// radar.offseq.com/threat/cve-20 26-71885-cwe-295-improper-cerMmastodonTechnologyCybersecurity13 h ago

    Security teams are being alerted to CVE-2026-71885, a critical vulnerability in Legion of the Bouncy Castle's BC-Java cryptography library. The flaw involves improper certificate validation (CWE-295), meaning affected Java applications could trust forged or invalid certificates, opening the door to man-in-the-middle attacks. Given how widely BC-Java is embedded in Java infrastructure, administrators are advised to track for patches and assess exposure.

  10. 10
    Bouncy Castle Java library hit by new signature verification flaw●CVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA https:// radar.offseq.com/threat/cve-20 26-71887-cwe-347-improper-vMmastodonTechnologyCybersecurity15 h ago

    A new vulnerability, CVE-2026-71887, has been disclosed affecting the Legion of the Bouncy Castle cryptography library for Java. The flaw is classed as CWE-347, improper verification of cryptographic signature, meaning the library may accept signatures it should reject. Security researchers are sharing the advisory and tracking potential impact on Java applications relying on the widely used library.

  11. 11
    GitLab patches critical AI Gateway flaw allowing command executionβ—πŸ€– GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform accessMmastodonTechnologyCybersecurity110 h ago

    GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.

  12. 12
    WordPress plugin Jeg Kit vulnerable to stored XSS flaw●Jeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant JavMmastodonTechnologyCybersecurity110 h ago

    Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.

  13. 13
    Cenovus Energy stock outpaces broader market gainsβ–ΌCenovus Energy (CVE) Beats Stock Market Upswing: What Investors Need to Knowβœ‰newsBusinessMarkets1 d ago

    Cenovus Energy shares have risen faster than the wider stock market, drawing attention from investors watching the Canadian oil and gas producer. The move comes amid broader strength in the market, with commentary focused on what the outperformance means for investors, including the company's position in the energy sector and its outlook going forward.

  14. 14
    Zoho's poor trust score raises patching concerns●Zoho holds a D trust score with 38 CVEs, 2 in CISA KEV, and 100% unpatched. SQLi and XSS dominate. Patch or pivot. httpsMmastodonTechnologyCybersecurity010 h ago

    A cybersecurity assessment gives Zoho a D trust score, citing 38 known vulnerabilities, two of which are listed in CISA's Known Exploited Vulnerabilities catalog, with none of the flaws patched. SQL injection and cross-site scripting account for most of the reported issues. Security commentators are urging organizations using Zoho products to either apply fixes promptly or reconsider the vendor.

  15. 15
    New analysis warns of economic doom approaching for Russia●New Video: Economic Doom Approaching for Russia | Ukraine War Poltical News Update https://www.youtube.com/watch?v=CVev9MmastodonWarUkraine321 h ago

    A new geopolitical news update argues that Russia's economy is heading toward serious trouble as the war in Ukraine continues. The piece points to Western sanctions and the strain of a war economy under Vladimir Putin as key pressures, framing the country's economic outlook as increasingly bleak.

  16. 16
    Critical Zammad vulnerability CVE-2026-102490 allows remote code executionβ—πŸ”΄ New security advisory: CVE-2026-102490 affects Zammad. β€’ Impact: Remote code execution or complete system compromise pMmastodonTechnologyCybersecurity118 h ago

    A new security advisory reports that CVE-2026-102490 affects Zammad, the open-source helpdesk and customer support platform. According to the advisory, the flaw could allow remote code execution and full system compromise, letting attackers gain complete control of affected servers. Administrators are urged to patch immediately or isolate exposed systems until updated.

  17. 17
    Microsoft tracks unauthenticated command injection flaw in mail serversβ–ΌUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570βœ‰newsTechnologyInternet2 d ago

    Microsoft is tracking CVE-2026-73570, a newly disclosed vulnerability that allows unauthenticated command injection on internet-facing mail servers. Because the flaw can be exploited without credentials and targets exposed systems, security teams are watching for signs of exploitation and awaiting patch guidance. Admins of mail infrastructure are being urged to assess exposure while details and fixes are confirmed.

  18. 18
    Critical Stirling PDF flaw with public exploit demands urgent patch●Details and a PoC are public for CVE-2026-85714, a 9.1 Stirling PDF RCE via crafted SQL import. Upgrade to version 2.13.MmastodonTechnologySoftware11 d ago

    A critical remote code execution vulnerability in Stirling PDF, tracked as CVE-2026-85714 and rated 9.1, has full technical details and a proof-of-concept exploit publicly available. The flaw stems from a crafted SQL import affecting the bundled H2 database. Administrators are urged to upgrade to version 2.13.2 immediately, as the public exploit makes attacks likely.

  19. 19
    GitLab AI Gateway flaw CVE-2026-90970 enables remote code execution●GitLab AI Gateway flaw CVE-2026-90970 enables RCE https:// fawkes.rocks/2026/10/02/gitlab -ai-gateway-flaw-cve-2026-9097MmastodonTechnologyAI120 h ago

    A security vulnerability tracked as CVE-2026-90970 has been disclosed in GitLab's AI Gateway, reportedly allowing remote code execution on affected systems. GitLab's AI Gateway sits in front of the company's AI-powered features, so a flaw there could expose organizations using the platform's AI tooling. Administrators are being urged to check their deployments and apply patches. Details on affected versions and exploitation are still limited.

  20. 20
    High-severity SQL injection flaw found in YesWikiβ—πŸŸ  CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}MmastodonTechnologyCybersecurity022 h ago

    A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.

  21. 21
    YesWiki security flaw lets attackers hit admin API routesβ—πŸŸ  CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthMmastodonTechnologyCybersecurity022 h ago

    A high-severity vulnerability, CVE-2026-104467, has been disclosed in YesWiki, a French open-source wiki software. Versions before 4.6.7 contain an authorization bypass in the ApiService::isAuthorized() function, allowing unauthenticated attackers to call admin-only API routes when public API mode is enabled. Administrators are urged to update to 4.6.7.

  22. 22
    Zitadel IAM flagged with D trust score over unpatched flaws●Zitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know youMmastodonTechnologyCybersecurity01 d ago

    Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.

  23. 23
    Infosec community shares joke artwork 'Several vulnerabilities'●I call this piece "Several vulnerabilities". # infosec # CVEMmastodonTechnologyCybersecurity51 d ago

    A member of the Australian information security community posted a piece titled 'Several vulnerabilities', tagged with infosec and CVE. The post is a light-hearted commentary circulating among cybersecurity practitioners, who often swap jokes about the steady stream of published vulnerabilities and advisories in their field.

  24. 24
    Keycloak Kerberos flaw lets network attackers hijack accounts●CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take overMmastodonTechnologyCybersecurity01 d ago

    A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.

  25. 25
    High-severity vulnerability disclosed in Apache Thrift Lua libraryβ—πŸš¨ EUVD-2026-91330 πŸ“Š Score: 8.7/10 (CVSS v3.1) πŸ“¦ Product: Apache Thrift 🏒 Vendor: Apache Software Foundation πŸ“… Updated: 2MmastodonTechnologyCybersecurity01 d ago

    A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.

  26. 26
    WordPress Super Forms plugin hit by high-severity privilege escalation flawβ—πŸŸ  CVE-2026-15897 - High (8.8) The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to PrivilegeMmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, CVE-2026-15897, has been disclosed in the Super Forms Drag & Drop Form Builder plugin for WordPress. The privilege escalation flaw affects all versions up to and including 6.3.316 and stems from the Register & Login add-on's before_email_success_msg() function. Site administrators are being urged to update the plugin to a patched version to avoid potential account takeover risks.

  27. 27
    Ninja Forms file uploads plugin hit by high-severity flawβ—πŸŸ  CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operatMmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, CVE-2026-92820 with a score of 8.1, has been disclosed in the Ninja Forms File Uploads plugin for WordPress. All versions up to and including 3.3.34 are affected. The flaw allows arbitrary file operations through the plugin's external Amazon S3 upload flow, which trusts an attacker-supplied file path submitted via a form. WordPress site administrators using the plugin are urged to update or disable it until a patched version is available.

  28. 28
    Critical authentication flaw disclosed in dplugins DevKit Pro●CVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro ( https:// radar.offseq.com/threat/cve-20 26-14378-cwe-287-impropeMmastodonTechnologyCybersecurity11 d ago

    A critical vulnerability, tracked as CVE-2026-14378, has been disclosed in DevKit Pro, a plugin product by dplugins for WordPress. The flaw is classified as CWE-287, improper authentication, meaning the plugin may fail to correctly verify user identity, potentially letting attackers gain unauthorized access to sites running it. Security trackers are flagging it as critical, and WordPress administrators are being urged to check whether they use the affected plugin and apply fixes or mitigations.

  29. 29
    WordPress plugin SiteOrigin Widgets Bundle hit by file inclusion flawβ—πŸŸ  CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion iMmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, CVE-2026-92174 scored 7.5, has been disclosed in the SiteOrigin Widgets Bundle plugin for WordPress. All versions up to and including 1.73.2 are affected by a local file inclusion flaw via the 'theme' parameter, which could let authenticated attackers with contributor-level access include sensitive files. Site owners are being urged to update the plugin promptly.

  30. 30
    Discord libdave hit by critical vulnerability CVE-2026-104480●Discord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 – https:// radar.offseq.com/threat/cvMmastodonTechnologyCybersecurity11 d ago

    A critical vulnerability tracked as CVE-2026-104480, rated 9.4 on the CVSS scale, has been reported in Discord's libdave library, affecting version 1.1.0. The flaw is classified as CWE-390, detection of an error condition without action, meaning errors can occur without proper handling. Security researchers are circulating details of the issue and urging users and developers to watch for patches or updated releases.

  31. 31
    Critical LDAP injection flaw hits Red Hat Directory Server 11●Red Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-StaMmastodonTechnologyCybersecurity11 d ago

    A critical vulnerability, CVE-2026-86345 with a CVSS score of 9, has been disclosed in Red Hat Directory Server 11. It allows on-path attackers to inject LDAP messages after StartTLS negotiation, potentially leading to authentication bypass. Security teams are being urged to restrict access to affected servers and follow Red Hat's advisory for remediation guidance.

  32. 32
    Op-Ed Critiques Jane Schoenbrun's 'Eroticverse' as Self-Indulgentβ–ΌOp-Ed: Jane Schoenbrun’s Self-Indulgent Movie Eroticverseβœ‰newsCultureFilm2 d ago

    InSession Film has published an opinion piece criticizing filmmaker Jane Schoenbrun, describing her body of work as a 'self-indulgent movie Eroticverse.' The essay takes issue with what it portrays as self-absorbed storytelling in Schoenbrun's films, adding to ongoing debate about her distinctive, internet-inflected style. Reaction so far appears limited, and the piece's specific arguments are not detailed beyond the headline.

  33. 33
    Oracle PeopleSoft faces criticism over unpatched vulnerabilities●Oracle PeopleSoft carries a D trust score. 44 CVEs, 33 rated critical or high, max CVSS 9.9 and 100% unpatched. Not oneMmastodonTechnologyCybersecurity11 d ago

    Security researchers flag Oracle PeopleSoft with a D trust score, citing 44 known vulnerabilities, 33 of them rated critical or high severity, with a maximum CVSS score of 9.9 and none of them patched. None appear in CISA's Known Exploited Vulnerabilities catalog, but commentators argue that is little comfort when fixes are absent. The discussion stresses that patch prioritization matters, and criticism is mounting over Oracle's slow remediation of flaws in enterprise software still widely used by large organizations.

  34. 34
    Cisco SD-WAN Manager flaw actively exploited, admins urged to patch●Attackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. PatcMmastodonTechnologyCybersecurity22 d ago

    Attackers are exploiting CVE-2026-76504, a critical authentication bypass vulnerability in Cisco SD-WAN Manager with a severity score of 9.8. The flaw allows unauthenticated access to the administrative API, potentially handing attackers full control of affected systems. Security sources say it is being actively exploited and are urging organisations to apply Cisco's patch immediately.

  35. 35
    Cisco Patches Actively Exploited Zero-Day in SD-WAN Manager●Cisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager Cisco released security updates for a zero-day vulnMmastodonTechnologyCybersecurity12 d ago

    Cisco has released security updates for Catalyst SD-WAN Manager to fix a zero-day vulnerability, tracked as CVE-2026-76504, that attackers are actively exploiting in the wild. The flaw allows unauthenticated remote attackers to gain administrator privileges on affected systems. Administrators are urged to apply the patches promptly, as exploitation is already underway and unpatched SD-WAN management consoles could give attackers broad control over enterprise networks.

  36. 36
    Critical unpatched flaw reported in gray-matter parser●CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patchMmastodonTechnologyCybersecurity01 d ago

    A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.

  37. 37
    Two Android 16 vulnerabilities disclosed: credential bypass and privilege escalation●CVE-2026-0016 and CVE-2026-0017 affect Google Android versions 16 and 16-qpr2. The first is a CredentialManager permissiMmastodonTechnologyCybersecurity12 d ago

    Security researchers have flagged two newly published vulnerabilities in Google Android 16 and 16-qpr2. CVE-2026-0016 is a CredentialManager permissions bypass that can expose local information, while CVE-2026-0017 is a BiometricService logic flaw allowing local privilege escalation. No exploitation in the wild has been reported so far. Users and administrators are advised to follow Google's security bulletins for patches.

  38. 38
    Dell patches critical Terraform Provider flaws exposing BMC trafficβ–ΌDell patched critical Dell Terraform Provider vulnerabilities. CVE-2026-91881 exposes BMC traffic to attackers. UpgradeMmastodonTechnologyCybersecurity12 d ago

    Dell has released patches for critical vulnerabilities in its Dell Terraform Provider, including CVE-2026-91881, which could let attackers intercept or expose BMC (baseboard management controller) traffic. Security researchers urge administrators using the provider in infrastructure-as-code environments to upgrade to the fixed versions as soon as possible to avoid potential credential or management-plane exposure.

  39. 39
    New CVE-2026-76570 flaw allows full system compromiseβ—πŸš¨ New security advisory: CVE-2026-76570 affects multiple systems. β€’ Impact: Remote code execution or complete system comMmastodonTechnologyCybersecurity11 d ago

    A new security advisory warns that CVE-2026-76570 affects multiple systems, potentially allowing remote code execution or complete system compromise. Attackers could gain full control of vulnerable machines, and administrators are urged to patch immediately or isolate affected systems until fixes are applied. Details of the affected software and full technical breakdown are circulating among security professionals.

  40. 40
    High-severity flaw in ASUS routers grants attackers root access●CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining rootMmastodonTechnologyCybersecurity12 d ago

    A newly published vulnerability, CVE-2026-13313, affects ASUS routers and is rated high severity with a CVSS score of 8.9. Authenticated attackers can exploit a debug code path to enable Telnet on the device, obtaining root command execution. Security researchers advise administrators to restrict management access and monitor for Telnet activity until ASUS releases patch details.