search
Server administration
Trends
- 1OpenSSL 4.0.3 Released as Security Patch, Update Nowβ# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 2Flamethrower: an open-source DNS testing utilityβπ§ Flamethrower β DNS performance and functional testing utility Flamethrower is a fast DNS testing utility for benchmark
Flamethrower is a fast, open-source tool for benchmarking and stress-testing DNS servers, supporting queries over UDP, TCP, DNS-over-TLS and DNS-over-HTTPS on Linux. It measures performance and functional behaviour of DNS infrastructure, letting administrators test how servers cope under load and verify protocol support.
- 3Digital infrastructure knowledge should not stay with specialistsβWer # digitaleInfrastruktur nutzt, sollte verstehen, wie sie funktioniert. Nicht, weil jede:r # Serveradmin werden muss
German-speaking online discussions are arguing that everyone who uses digital infrastructure should understand how it works. The argument is not that everyone must become a server administrator, but that knowledge about DNS, backups, migration, security and recovery should not remain in the hands of a few specialists. Supporters see basic technical literacy as a shared responsibility in an increasingly digital society.
- 4Calnode v0.10.1 Ships with Security Updates and NethServer ModuleβCalnode v0.10.1 Released with Security Updates and One-Click NethServer Module π° Original title: Calnode v0.10.1: the re
Calnode has released version 0.10.1, an update that includes security fixes and a new one-click module for deploying the software on NethServer. The release is being described as shaped by feedback from the project's deployers, and it is drawing attention from self-hosting and server administration communities interested in simplified deployment and patched vulnerabilities.
- 5LiteSpeed Web Server fixes internal redirect validation flaw CVE-2026-93903βΌCVE-2026-93903: LiteSpeed Web Server (LSWS) from litespeedtech mishandles internal redirect URL validation in a certain
A vulnerability tracked as CVE-2026-93903 affects LiteSpeed Technologies' LiteSpeed Web Server, which mishandles internal redirect URL validation in a specific corner case. All versions before 6.3.7 build 1 are affected. No exploitation has been confirmed so far. Administrators are advised to update to version 6.3.7 build 1 to resolve the issue, and the flaw is being flagged across security communities.
- 6WordPress Flaw Turns One Admin Click Into Server TakeoverβClick2Shell: A WordPress Theme-Install Flaw That Turns One Admin Click Into Server Code Execution If your organisation r
Security researchers have disclosed a WordPress vulnerability, dubbed Click2Shell, in which a single link opened by a site administrator can trigger malicious theme installation and full remote code execution on the server. Because WordPress powers a large share of websites, organisations are being urged to review admin practices and apply patches.
- 7GitLab critical flaw already drawing internet-wide scansβGitLabβs critical flaw is already drawing internet-wide probes https:// cyberscoop.com/gitlab-critical -flaws-path-trave
A critical path traversal vulnerability in GitLab is being actively probed by attackers scanning the entire internet, according to CyberScoop reporting. Security practitioners are sharing warnings and urging administrators to patch their GitLab instances immediately, as exploitation attempts are already under way against exposed servers before wider damage occurs.
- 8Apache HTTP Server vulnerability EUVD-2026-90892 disclosedβπ¨ EUVD-2026-90892 π Score: n/a π¦ Product: Apache HTTP Server π’ Vendor: Apache Software Foundation π Updated: 2026-10-01
A new vulnerability, EUVD-2026-90892, has been recorded for the Apache HTTP Server, maintained by the Apache Software Foundation. The flaw involves missing authentication checks in the mod_auth_digest module in versions before 2.4.69, potentially allowing unauthenticated access. Users are advised to update to a patched release. The entry was updated on 1 October 2026.
- 9Critical vulnerability CVE-2026-62308 disclosed in TugtainerβΌπ¨ CVE-2026-62308 β CVSS 9.1 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical vulnerability, CVE-2026-62308 with a CVSS score of 9.1, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions prior to 1.30.6 allow an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs, a server-side request forgery flaw. Admins running affected versions are urged to update to 1.30.6 or later.
- 10High-severity file upload flaw disclosed in BurgerEditorβπ¨ EUVD-2026-75229 π Score: 8.5/10 (CVSS v3.1) π¦ Product: BurgerEditor, BurgerEditor π’ Vendor: D-ZERO CO.,LTD. π Publishe
A vulnerability tracked as EUVD-2026-75229 has been published for BurgerEditor, a product by Japanese vendor D-ZERO Co., Ltd. Versions 3.2.0 through 3.4.0 contain an unrestricted file upload flaw that allows files with dangerous types to be uploaded, a weakness that can enable remote code execution on affected servers. The issue carries a CVSS v3.1 score of 8.5, classified as high severity. It was published on 10 September 2026 and updated on 1 October 2026. Administrators running affected versions are advised to update promptly.
- 11Eight Apache MINA SSHD flaws allow authentication bypassβEight Apache MINA SSHD vulnerabilities allow authentication bypass. Fix critical Apache MINA SSHD vulnerabilities by upg
Security researchers have disclosed eight vulnerabilities in Apache MINA SSHD, the Java library for SSH connections, that together can allow authentication bypass. The flaws, tracked under CVE identifiers including CVE-2026-94052, CVE-2026-94053 and CVE-2026-77185, affect applications embedding the library. Administrators are urged to upgrade their Java applications promptly to patched versions.
- 12Critical CVE-2026-70356 flagged in TMS file upload endpointβπ¨ CVE-2026-70356 β CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a
A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.
- 13Critical vulnerability found in Docker update tool Tugtainerβπ¨ CVE-2026-55181 β CVSS 9.4 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical vulnerability, CVE-2026-55181 with a CVSS score of 9.4, has been disclosed in Tugtainer, a self-hosted application used to automate updates of Docker containers. Versions before 1.30.3 allow OIDC authentication to be initiated even when OIDC is disabled, potentially letting attackers bypass authentication. Administrators are urged to upgrade to version 1.30.3 or later.
- 14High-Severity Flaw Reported in Pexip Infinity Video Conferencing Platformβπ CVE-2026-103101 - High (8.6) Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in
A high-severity vulnerability, CVE-2026-103101 with a CVSS score of 8.6, affects Pexip Infinity versions 30.0 through 40.x before 41.0. The flaw stems from improper input validation in the web server component and could allow a malicious attacker to render a Pexip Infinity node inaccessible, disrupting video conferencing services. Administrators are being urged to update to version 41.0 or later to close the gap.