search
Server administration
Trends
- 1Multiple vulnerabilities discovered in the Linux kernelβSeveral vulnerabilities have been discovered in the Linux kernel
Several security vulnerabilities have been discovered in the Linux kernel. The finding, reported via LWN, is drawing attention from developers and system administrators, who are expected to watch for patches and updated kernel releases. Users of Linux-based systems are advised to apply fixes as distributions push out security updates.
- 2OpenSSL 4.0.3 Released as Security Patch, Update Nowβ# OpenSSL 4.0.3 Is Out as Another # Security Patch Release, Update Now https:// 9to5linux.com/openssl-4-0-3-is -out-as-a
The OpenSSL project has released version 4.0.3, another security patch release addressing vulnerabilities in the widely used encryption library. The news is spreading through the free and open source software community, where users are being urged to update their systems promptly. As OpenSSL underpins encrypted connections across much of the internet, admins of Linux servers and other deployments are expected to apply the patch quickly.
- 3Veganism.social emerges as a dedicated vegan Mastodon serverβVeganism.social is a Mastodon server for vegans to make friends and interact with the wider Fediverse. This server has a
Veganism.social is being highlighted as a Mastodon server where vegans can connect, make friends and interact with the wider Fediverse. The server allows posts of up to 10,000 characters, longer than many mainstream platforms permit, and directs newcomers to its about page for details on joining and contacting its administrator.
- 4Calnode v0.10.1 Ships with Security Updates and NethServer ModuleβCalnode v0.10.1 Released with Security Updates and One-Click NethServer Module π° Original title: Calnode v0.10.1: the re
Calnode has released version 0.10.1, an update that includes security fixes and a new one-click module for deploying the software on NethServer. The release is being described as shaped by feedback from the project's deployers, and it is drawing attention from self-hosting and server administration communities interested in simplified deployment and patched vulnerabilities.
- 5Guide: Installing DNSControl on Ubuntu VPS for PowerDNS ManagementβHow to Install # DNSControl on # Ubuntu # VPS to Manage # PowerDNS This article demonstrates how to install DNSControl o
A new tutorial walks through installing DNSControl, an open-source tool for managing DNS records across multiple providers, on an Ubuntu VPS and configuring it to control PowerDNS servers. The guide covers what DNSControl is, the installation steps, and how to connect it to PowerDNS, aimed at administrators who want to automate and centralize DNS management from the command line.
- 6Roundcube Webmail SQL Injection Flaw Actively ExploitedβΌRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
- 7New guide walks through deploying Nagios Core on Ubuntu VPSβπ Deploy # Nagios on # Ubuntu # VPS This guide walks through deploying Nagios Core on an Ubuntu VPS, from system prep to
A step-by-step tutorial for deploying Nagios Core on an Ubuntu virtual private server has been published, covering system preparation, web access setup, plugins, and host and service configuration through to security hardening. The commands target Ubuntu 22.04 LTS, with notes that they work similarly on 20.04 and 24.04, giving administrators a practical open-source server monitoring option.
- 8Step-by-step guide to installing Directus on AlmaLinuxβHow to Install # Directus on # AlmaLinux # VPS Here's a step-by-step guide detailing how to install Directus on AlmaLinu
A new tutorial walks through installing Directus, the open-source headless CMS and data platform, on an AlmaLinux VPS. The guide covers what Directus is β a tool for managing and interacting with databases through an API-first interface β and details the setup steps for server administrators. It reflects steady interest in self-hosting flexible CMS alternatives on enterprise-grade Linux distributions.
- 9Critical FortiMail Zero-Day Flaw Exploited in Active AttacksβCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Security researchers report that a critical zero-day vulnerability in Fortinet's FortiMail product is being exploited in real-world attacks. The flaw allows unauthenticated attackers to write arbitrary files, potentially enabling remote code execution on affected email security servers. Administrators are urged to apply patches and restrict exposure. Fortinet has faced a series of exploited vulnerabilities in recent months, keeping the company under scrutiny.
- 10New guide takes sysadmins from Bash basics to production scriptsβBash scripting per sistemisti: dai fondamentali agli script di produzione pronti per cron # tech https:// spcnet.it/bash
A new Italian-language tutorial published on SPCNet walks system administrators through Bash scripting, starting from core fundamentals and building up to production-ready scripts suitable for scheduling with cron. The guide is being shared in tech communities, where users highlight it as a practical resource for automating routine server administration tasks.
- 11Flamethrower: an open-source DNS testing utilityβπ§ Flamethrower β DNS performance and functional testing utility Flamethrower is a fast DNS testing utility for benchmark
Flamethrower is a fast, open-source tool for benchmarking and stress-testing DNS servers, supporting queries over UDP, TCP, DNS-over-TLS and DNS-over-HTTPS on Linux. It measures performance and functional behaviour of DNS infrastructure, letting administrators test how servers cope under load and verify protocol support.
- 12LiteSpeed Web Server fixes internal redirect validation flaw CVE-2026-93903βΌCVE-2026-93903: LiteSpeed Web Server (LSWS) from litespeedtech mishandles internal redirect URL validation in a certain
A vulnerability tracked as CVE-2026-93903 affects LiteSpeed Technologies' LiteSpeed Web Server, which mishandles internal redirect URL validation in a specific corner case. All versions before 6.3.7 build 1 are affected. No exploitation has been confirmed so far. Administrators are advised to update to version 6.3.7 build 1 to resolve the issue, and the flaw is being flagged across security communities.
- 13German Green politician's infosec idea draws support onlineβRE: https:// gruene.social/@sven/1173781578 04337854 Ui das klingt doch nach einer mega Idee o.O Geren # rt fΓΌr mehr Fee
Sven, a member of the German Greens posting on gruene.social, has floated an idea in the infosec and sysadmin field that a fellow administrator is publicly endorsing as a strong one. The supporter is calling for more feedback and greater reach for the proposal, using the hashtags admin and infosec. The details of the idea itself are not spelled out in the exchange.
- 14Digital infrastructure knowledge should not stay with specialistsβWer # digitaleInfrastruktur nutzt, sollte verstehen, wie sie funktioniert. Nicht, weil jede:r # Serveradmin werden muss
German-speaking online discussions are arguing that everyone who uses digital infrastructure should understand how it works. The argument is not that everyone must become a server administrator, but that knowledge about DNS, backups, migration, security and recovery should not remain in the hands of a few specialists. Supporters see basic technical literacy as a shared responsibility in an increasingly digital society.
- 15Nginx UI offers browser-based dashboard for server managementβNginx UI offers a polished open-source dashboard for managing sites, configs, SSL certificates, logs, upstreams, nodes,
Nginx UI, an open-source web interface, is drawing attention as a polished dashboard for managing Nginx servers. It lets administrators handle sites, configuration files, SSL certificates, logs, upstreams and multiple nodes directly from a browser, reducing reliance on manual config editing. Open-source administration panels like this typically circulate widely among sysadmins and Linux users looking to simplify server maintenance.
- 16Nextcloud pitched as privacy-focused alternative to Google DriveβTake back your data privacy! Stop paying monthly per-user fees to Google Drive or Dropbox. # Nextcloud gives you a priva
Supporters of Nextcloud are urging users to take back control of their data by ditching paid monthly subscriptions to Google Drive or Dropbox. The open-source, self-hosted platform offers file sync, document editing and video calls under the user's own administration, and posts are pointing people toward guides on installing and optimizing it on their own servers.
- 17Critical vulnerability CVE-2026-62308 disclosed in TugtainerβΌπ¨ CVE-2026-62308 β CVSS 9.1 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical vulnerability, CVE-2026-62308 with a CVSS score of 9.1, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions prior to 1.30.6 allow an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs, a server-side request forgery flaw. Admins running affected versions are urged to update to 1.30.6 or later.
- 18Apache HTTP Server 2.4.69 Patches 20 Security VulnerabilitiesβApache HTTP Server 2.4.69 Fixes 20 Security Vulnerabilities https:// lemmy.world/post/52617442
The Apache Software Foundation has released HTTP Server 2.4.69, a maintenance update that fixes 20 security vulnerabilities in the widely used open-source web server. Admins are being urged to update their installations promptly, as the web server powers a large share of websites worldwide and unpatched flaws can expose servers to attack.
- 19Admins Urged to Check NetScaler Versions Over WeekendβIf you're reading this on your phone while staring at some flickering server rack, stop and check your NetScaler version
Security practitioners are pressing organisations to immediately verify their Citrix NetScaler versions, warning that a known vulnerability demands patching even on a weekend. The message urges admins not to wait until Monday, reflecting ongoing concern in the infosec community about unpatched edge devices being exploited. Administrators are advised to confirm their deployed versions and apply fixes without delay.
- 20Critical CVE-2026-70356 flagged in TMS file upload endpointβπ¨ CVE-2026-70356 β CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a
A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.
- 21Critical Zammad vulnerability CVE-2026-102490 allows remote code executionβπ΄ New security advisory: CVE-2026-102490 affects Zammad. β’ Impact: Remote code execution or complete system compromise p
A new security advisory reports that CVE-2026-102490 affects Zammad, the open-source helpdesk and customer support platform. According to the advisory, the flaw could allow remote code execution and full system compromise, letting attackers gain complete control of affected servers. Administrators are urged to patch immediately or isolate exposed systems until updated.
- 22Fortinet FortiMail Bug CVE-2026-104286 Actively ExploitedβFortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert
Fortinet has a critical vulnerability, tracked as CVE-2026-104286, in its FortiMail email security product. The flaw involves path traversal combined with NULL byte handling, and security researchers report it is being actively exploited in the wild. Administrators are being urged to apply patches immediately to prevent attackers from compromising mail servers.
- 23GitLab critical flaw already drawing internet-wide scansβGitLabβs critical flaw is already drawing internet-wide probes https:// cyberscoop.com/gitlab-critical -flaws-path-trave
A critical path traversal vulnerability in GitLab is being actively probed by attackers scanning the entire internet, according to CyberScoop reporting. Security practitioners are sharing warnings and urging administrators to patch their GitLab instances immediately, as exploitation attempts are already under way against exposed servers before wider damage occurs.
- 24High-Severity Flaw Reported in Pexip Infinity Video Conferencing Platformβπ CVE-2026-103101 - High (8.6) Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in
A high-severity vulnerability, CVE-2026-103101 with a CVSS score of 8.6, affects Pexip Infinity versions 30.0 through 40.x before 41.0. The flaw stems from improper input validation in the web server component and could allow a malicious attacker to render a Pexip Infinity node inaccessible, disrupting video conferencing services. Administrators are being urged to update to version 41.0 or later to close the gap.
- 25WordPress Flaw Turns One Admin Click Into Server TakeoverβClick2Shell: A WordPress Theme-Install Flaw That Turns One Admin Click Into Server Code Execution If your organisation r
Security researchers have disclosed a WordPress vulnerability, dubbed Click2Shell, in which a single link opened by a site administrator can trigger malicious theme installation and full remote code execution on the server. Because WordPress powers a large share of websites, organisations are being urged to review admin practices and apply patches.
- 26Apache HTTP Server vulnerability EUVD-2026-90892 disclosedβπ¨ EUVD-2026-90892 π Score: n/a π¦ Product: Apache HTTP Server π’ Vendor: Apache Software Foundation π Updated: 2026-10-01
A new vulnerability, EUVD-2026-90892, has been recorded for the Apache HTTP Server, maintained by the Apache Software Foundation. The flaw involves missing authentication checks in the mod_auth_digest module in versions before 2.4.69, potentially allowing unauthenticated access. Users are advised to update to a patched release. The entry was updated on 1 October 2026.
- 27Eight Apache MINA SSHD flaws allow authentication bypassβEight Apache MINA SSHD vulnerabilities allow authentication bypass. Fix critical Apache MINA SSHD vulnerabilities by upg
Security researchers have disclosed eight vulnerabilities in Apache MINA SSHD, the Java library for SSH connections, that together can allow authentication bypass. The flaws, tracked under CVE identifiers including CVE-2026-94052, CVE-2026-94053 and CVE-2026-77185, affect applications embedding the library. Administrators are urged to upgrade their Java applications promptly to patched versions.
- 28High-severity file upload flaw disclosed in BurgerEditorβπ¨ EUVD-2026-75229 π Score: 8.5/10 (CVSS v3.1) π¦ Product: BurgerEditor, BurgerEditor π’ Vendor: D-ZERO CO.,LTD. π Publishe
A vulnerability tracked as EUVD-2026-75229 has been published for BurgerEditor, a product by Japanese vendor D-ZERO Co., Ltd. Versions 3.2.0 through 3.4.0 contain an unrestricted file upload flaw that allows files with dangerous types to be uploaded, a weakness that can enable remote code execution on affected servers. The issue carries a CVSS v3.1 score of 8.5, classified as high severity. It was published on 10 September 2026 and updated on 1 October 2026. Administrators running affected versions are advised to update promptly.
- 29Critical vulnerability found in Docker update tool Tugtainerβπ¨ CVE-2026-55181 β CVSS 9.4 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical vulnerability, CVE-2026-55181 with a CVSS score of 9.4, has been disclosed in Tugtainer, a self-hosted application used to automate updates of Docker containers. Versions before 1.30.3 allow OIDC authentication to be initiated even when OIDC is disabled, potentially letting attackers bypass authentication. Administrators are urged to upgrade to version 1.30.3 or later.