search
CVE
Trends
- 1EU Reporting Rules Put Linux Vulnerability Management Under PressureβThe # EU Is About to Make # Linux 's # Vulnerability Management Problem Harder to Ignore More # CVE , sprawling deployme
The EU's upcoming cybersecurity reporting requirements are set to expose long-standing weaknesses in how Linux vulnerabilities are tracked and patched. The number of published CVEs has grown sharply, and sprawling deployments make it harder for organisations to prove which systems are affected. Under the new rules, patching alone may not suffice: teams will need documented evidence of their vulnerability handling, turning compliance into a pressing operational challenge for Linux users across Europe.
- 2Critical flaw in Apache OpenOffice lets documents run codeβΌCVE-2026-59265: A critical flaw in Apache OpenOffice's Java integration lets a crafted untrusted document execute arbitr
A critical vulnerability, tracked as CVE-2026-59265, has been found in Apache OpenOffice's Java integration. Opening a crafted untrusted document can allow arbitrary code execution on the affected machine. Versions 4.1.16 and earlier are affected, and no exploitation has been confirmed so far. A fix is expected in version 4.1.17; users are advised to disable the Java runtime as an interim measure.
- 3GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityβπ¨ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI Gat
GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.
- 4GitLab Rushes Emergency Fixes for Exploited AI Gateway FlawsβGitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws GitLab released emer
GitLab has released emergency security patches addressing two critical vulnerabilities: a remote code execution flaw in its AI Gateway, tracked as CVE-2026-90970, and a maximum-severity path traversal issue. Both flaws are reportedly being actively exploited, prompting the unusually urgent rollout. Security teams are being urged to apply the updates immediately, with the disclosures fueling renewed discussion about securing AI infrastructure.
- 5YesWiki hit by nine vulnerabilities including SQL injection flawβπ¨ YesWiki 9 CVEs β CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requir
Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.
- 6Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3βCritical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a pa
A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.
- 7Critical vulnerability found in NASA's AIT-Core softwareβNASA-AMMOS AIT-Core β€3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to
NASA's AMMOS AIT-Core toolkit, used for spacecraft ground systems, has a critical vulnerability tracked as CVE-2026-105105. The flaw affects versions up to 3.1.1: its ZeroMQ bus ships without authentication, potentially exposing spacecraft commands and telemetry to remote attackers. NASA has released version 3.1.2, which restricts bus access to the local loopback interface, and users are urged to upgrade immediately.
- 8SourceHut account takeover flaw found in build log renderingβSourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 https:// reddthat.com/post/74210240
A security vulnerability in SourceHut, tracked as CVE-2026-92973, reportedly allowed account takeover through malicious build logs. The flaw involved cross-site scripting in the ansi2html.py script used to render logs, letting attackers inject code that could hijack sessions. Developers and security researchers are discussing the disclosure and how the issue was handled.
- 9Critical CVE-2026-71885 flagged in Bouncy Castle BC-JavaβCRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA ( https:// radar.offseq.com/threat/cve-20 26-71885-cwe-295-improper-cer
Security teams are being alerted to CVE-2026-71885, a critical vulnerability in Legion of the Bouncy Castle's BC-Java cryptography library. The flaw involves improper certificate validation (CWE-295), meaning affected Java applications could trust forged or invalid certificates, opening the door to man-in-the-middle attacks. Given how widely BC-Java is embedded in Java infrastructure, administrators are advised to track for patches and assess exposure.
- 10Bouncy Castle Java library hit by new signature verification flawβCVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA https:// radar.offseq.com/threat/cve-20 26-71887-cwe-347-improper-v
A new vulnerability, CVE-2026-71887, has been disclosed affecting the Legion of the Bouncy Castle cryptography library for Java. The flaw is classed as CWE-347, improper verification of cryptographic signature, meaning the library may accept signatures it should reject. Security researchers are sharing the advisory and tracking potential impact on Java applications relying on the widely used library.
- 11GitLab patches critical AI Gateway flaw allowing command executionβπ€ GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access
GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.
- 12WordPress plugin Jeg Kit vulnerable to stored XSS flawβJeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant Jav
Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.
- 13Cenovus Energy stock outpaces broader market gainsβΌCenovus Energy (CVE) Beats Stock Market Upswing: What Investors Need to Know
Cenovus Energy shares have risen faster than the wider stock market, drawing attention from investors watching the Canadian oil and gas producer. The move comes amid broader strength in the market, with commentary focused on what the outperformance means for investors, including the company's position in the energy sector and its outlook going forward.
- 14Zoho's poor trust score raises patching concernsβZoho holds a D trust score with 38 CVEs, 2 in CISA KEV, and 100% unpatched. SQLi and XSS dominate. Patch or pivot. https
A cybersecurity assessment gives Zoho a D trust score, citing 38 known vulnerabilities, two of which are listed in CISA's Known Exploited Vulnerabilities catalog, with none of the flaws patched. SQL injection and cross-site scripting account for most of the reported issues. Security commentators are urging organizations using Zoho products to either apply fixes promptly or reconsider the vendor.
- 15New analysis warns of economic doom approaching for RussiaβNew Video: Economic Doom Approaching for Russia | Ukraine War Poltical News Update https://www.youtube.com/watch?v=CVev9
A new geopolitical news update argues that Russia's economy is heading toward serious trouble as the war in Ukraine continues. The piece points to Western sanctions and the strain of a war economy under Vladimir Putin as key pressures, framing the country's economic outlook as increasingly bleak.
- 16Critical Zammad vulnerability CVE-2026-102490 allows remote code executionβπ΄ New security advisory: CVE-2026-102490 affects Zammad. β’ Impact: Remote code execution or complete system compromise p
A new security advisory reports that CVE-2026-102490 affects Zammad, the open-source helpdesk and customer support platform. According to the advisory, the flaw could allow remote code execution and full system compromise, letting attackers gain complete control of affected servers. Administrators are urged to patch immediately or isolate exposed systems until updated.
- 17Microsoft tracks unauthenticated command injection flaw in mail serversβΌUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft is tracking CVE-2026-73570, a newly disclosed vulnerability that allows unauthenticated command injection on internet-facing mail servers. Because the flaw can be exploited without credentials and targets exposed systems, security teams are watching for signs of exploitation and awaiting patch guidance. Admins of mail infrastructure are being urged to assess exposure while details and fixes are confirmed.
- 18Critical Stirling PDF flaw with public exploit demands urgent patchβDetails and a PoC are public for CVE-2026-85714, a 9.1 Stirling PDF RCE via crafted SQL import. Upgrade to version 2.13.
A critical remote code execution vulnerability in Stirling PDF, tracked as CVE-2026-85714 and rated 9.1, has full technical details and a proof-of-concept exploit publicly available. The flaw stems from a crafted SQL import affecting the bundled H2 database. Administrators are urged to upgrade to version 2.13.2 immediately, as the public exploit makes attacks likely.
- 19GitLab AI Gateway flaw CVE-2026-90970 enables remote code executionβGitLab AI Gateway flaw CVE-2026-90970 enables RCE https:// fawkes.rocks/2026/10/02/gitlab -ai-gateway-flaw-cve-2026-9097
A security vulnerability tracked as CVE-2026-90970 has been disclosed in GitLab's AI Gateway, reportedly allowing remote code execution on affected systems. GitLab's AI Gateway sits in front of the company's AI-powered features, so a flaw there could expose organizations using the platform's AI tooling. Administrators are being urged to check their deployments and apply patches. Details on affected versions and exploitation are still limited.
- 20High-severity SQL injection flaw found in YesWikiβπ CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}
A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.
- 21YesWiki security flaw lets attackers hit admin API routesβπ CVE-2026-104467 - High (8.1) YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuth
A high-severity vulnerability, CVE-2026-104467, has been disclosed in YesWiki, a French open-source wiki software. Versions before 4.6.7 contain an authorization bypass in the ApiService::isAuthorized() function, allowing unauthenticated attackers to call admin-only API routes when public API mode is enabled. Administrators are urged to update to 4.6.7.
- 22Zitadel IAM flagged with D trust score over unpatched flawsβZitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know you
Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.
- 23Infosec community shares joke artwork 'Several vulnerabilities'βI call this piece "Several vulnerabilities". # infosec # CVE
A member of the Australian information security community posted a piece titled 'Several vulnerabilities', tagged with infosec and CVE. The post is a light-hearted commentary circulating among cybersecurity practitioners, who often swap jokes about the steady stream of published vulnerabilities and advisories in their field.
- 24Keycloak Kerberos flaw lets network attackers hijack accountsβCVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take over
A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.
- 25High-severity vulnerability disclosed in Apache Thrift Lua libraryβπ¨ EUVD-2026-91330 π Score: 8.7/10 (CVSS v3.1) π¦ Product: Apache Thrift π’ Vendor: Apache Software Foundation π Updated: 2
A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.
- 26WordPress Super Forms plugin hit by high-severity privilege escalation flawβπ CVE-2026-15897 - High (8.8) The Super Forms β Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege
A high-severity vulnerability, CVE-2026-15897, has been disclosed in the Super Forms Drag & Drop Form Builder plugin for WordPress. The privilege escalation flaw affects all versions up to and including 6.3.316 and stems from the Register & Login add-on's before_email_success_msg() function. Site administrators are being urged to update the plugin to a patched version to avoid potential account takeover risks.
- 27Ninja Forms file uploads plugin hit by high-severity flawβπ CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operat
A high-severity vulnerability, CVE-2026-92820 with a score of 8.1, has been disclosed in the Ninja Forms File Uploads plugin for WordPress. All versions up to and including 3.3.34 are affected. The flaw allows arbitrary file operations through the plugin's external Amazon S3 upload flow, which trusts an attacker-supplied file path submitted via a form. WordPress site administrators using the plugin are urged to update or disable it until a patched version is available.
- 28Critical authentication flaw disclosed in dplugins DevKit ProβCVE-2026-14378 | CRITICAL vuln in dplugins DevKit Pro ( https:// radar.offseq.com/threat/cve-20 26-14378-cwe-287-imprope
A critical vulnerability, tracked as CVE-2026-14378, has been disclosed in DevKit Pro, a plugin product by dplugins for WordPress. The flaw is classified as CWE-287, improper authentication, meaning the plugin may fail to correctly verify user identity, potentially letting attackers gain unauthorized access to sites running it. Security trackers are flagging it as critical, and WordPress administrators are being urged to check whether they use the affected plugin and apply fixes or mitigations.
- 29WordPress plugin SiteOrigin Widgets Bundle hit by file inclusion flawβπ CVE-2026-92174 - High (7.5) The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion i
A high-severity vulnerability, CVE-2026-92174 scored 7.5, has been disclosed in the SiteOrigin Widgets Bundle plugin for WordPress. All versions up to and including 1.73.2 are affected by a local file inclusion flaw via the 'theme' parameter, which could let authenticated attackers with contributor-level access include sensitive files. Site owners are being urged to update the plugin promptly.
- 30Discord libdave hit by critical vulnerability CVE-2026-104480βDiscord libdave CRITICAL vuln (CVE-2026-104480, CVSS 9.4): Affected versions 1.1.0 β https:// radar.offseq.com/threat/cv
A critical vulnerability tracked as CVE-2026-104480, rated 9.4 on the CVSS scale, has been reported in Discord's libdave library, affecting version 1.1.0. The flaw is classified as CWE-390, detection of an error condition without action, meaning errors can occur without proper handling. Security researchers are circulating details of the issue and urging users and developers to watch for patches or updated releases.
- 31Critical LDAP injection flaw hits Red Hat Directory Server 11βRed Hat Directory Server 11: CVE-2026-86345 (CRITICAL, CVSS 9) allows on-path attackers to inject LDAP messages post-Sta
A critical vulnerability, CVE-2026-86345 with a CVSS score of 9, has been disclosed in Red Hat Directory Server 11. It allows on-path attackers to inject LDAP messages after StartTLS negotiation, potentially leading to authentication bypass. Security teams are being urged to restrict access to affected servers and follow Red Hat's advisory for remediation guidance.
- 32Op-Ed Critiques Jane Schoenbrun's 'Eroticverse' as Self-IndulgentβΌOp-Ed: Jane Schoenbrunβs Self-Indulgent Movie Eroticverse
InSession Film has published an opinion piece criticizing filmmaker Jane Schoenbrun, describing her body of work as a 'self-indulgent movie Eroticverse.' The essay takes issue with what it portrays as self-absorbed storytelling in Schoenbrun's films, adding to ongoing debate about her distinctive, internet-inflected style. Reaction so far appears limited, and the piece's specific arguments are not detailed beyond the headline.
- 33Oracle PeopleSoft faces criticism over unpatched vulnerabilitiesβOracle PeopleSoft carries a D trust score. 44 CVEs, 33 rated critical or high, max CVSS 9.9 and 100% unpatched. Not one
Security researchers flag Oracle PeopleSoft with a D trust score, citing 44 known vulnerabilities, 33 of them rated critical or high severity, with a maximum CVSS score of 9.9 and none of them patched. None appear in CISA's Known Exploited Vulnerabilities catalog, but commentators argue that is little comfort when fixes are absent. The discussion stresses that patch prioritization matters, and criticism is mounting over Oracle's slow remediation of flaws in enterprise software still widely used by large organizations.
- 34Cisco SD-WAN Manager flaw actively exploited, admins urged to patchβAttackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patc
Attackers are exploiting CVE-2026-76504, a critical authentication bypass vulnerability in Cisco SD-WAN Manager with a severity score of 9.8. The flaw allows unauthenticated access to the administrative API, potentially handing attackers full control of affected systems. Security sources say it is being actively exploited and are urging organisations to apply Cisco's patch immediately.
- 35Cisco Patches Actively Exploited Zero-Day in SD-WAN ManagerβCisco Patches Actively Exploited Zero-Day in Catalyst SD-WAN Manager Cisco released security updates for a zero-day vuln
Cisco has released security updates for Catalyst SD-WAN Manager to fix a zero-day vulnerability, tracked as CVE-2026-76504, that attackers are actively exploiting in the wild. The flaw allows unauthenticated remote attackers to gain administrator privileges on affected systems. Administrators are urged to apply the patches promptly, as exploitation is already underway and unpatched SD-WAN management consoles could give attackers broad control over enterprise networks.
- 36Critical unpatched flaw reported in gray-matter parserβCVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch
A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.
- 37Two Android 16 vulnerabilities disclosed: credential bypass and privilege escalationβCVE-2026-0016 and CVE-2026-0017 affect Google Android versions 16 and 16-qpr2. The first is a CredentialManager permissi
Security researchers have flagged two newly published vulnerabilities in Google Android 16 and 16-qpr2. CVE-2026-0016 is a CredentialManager permissions bypass that can expose local information, while CVE-2026-0017 is a BiometricService logic flaw allowing local privilege escalation. No exploitation in the wild has been reported so far. Users and administrators are advised to follow Google's security bulletins for patches.
- 38Dell patches critical Terraform Provider flaws exposing BMC trafficβΌDell patched critical Dell Terraform Provider vulnerabilities. CVE-2026-91881 exposes BMC traffic to attackers. Upgrade
Dell has released patches for critical vulnerabilities in its Dell Terraform Provider, including CVE-2026-91881, which could let attackers intercept or expose BMC (baseboard management controller) traffic. Security researchers urge administrators using the provider in infrastructure-as-code environments to upgrade to the fixed versions as soon as possible to avoid potential credential or management-plane exposure.
- 39New CVE-2026-76570 flaw allows full system compromiseβπ¨ New security advisory: CVE-2026-76570 affects multiple systems. β’ Impact: Remote code execution or complete system com
A new security advisory warns that CVE-2026-76570 affects multiple systems, potentially allowing remote code execution or complete system compromise. Attackers could gain full control of vulnerable machines, and administrators are urged to patch immediately or isolate affected systems until fixes are applied. Details of the affected software and full technical breakdown are circulating among security professionals.
- 40High-severity flaw in ASUS routers grants attackers root accessβCVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root
A newly published vulnerability, CVE-2026-13313, affects ASUS routers and is rated high severity with a CVSS score of 8.9. Authenticated attackers can exploit a debug code path to enable Telnet on the device, obtaining root command execution. Security researchers advise administrators to restrict management access and monitor for Telnet activity until ASUS releases patch details.