MikeTrendsTrends right now

search

vss

Trends

  1. 1
    CISA Flags Actively Exploited Critical FortiMail Flaw●CISA adds CVE-2026-104286 (CVSS 9.8) to KEVβ€”critical flaw in Fortinet FortiMail allowing unauthenticated attackers to wrMmastodonTechnologyCybersecurity11 h ago

    CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog after reports of active attacks. The flaw, rated 9.8 out of 10 in severity, affects Fortinet's FortiMail and lets unauthenticated attackers write arbitrary files on vulnerable servers. Security teams are urged to patch immediately, as the flaw is described as a zero-day already being exploited in the wild.

  2. 2
    ZITADEL hit by seven vulnerabilities enabling account takeover●ZITADEL cluster β€” 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header β†’ issue passkey enrollment for anyMmastodonTechnologyCybersecurity22 h ago

    Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.

  3. 3
    Citrix NetScaler SAML zero-day actively exploited, added to CISA KEVβ—πŸš¨ Citrix NetScaler SAML zero-day (CVE-2026-88779, CVSS 8.7) in CISA KEV. Actively exploited. Memory overflow in SAML hanMmastodonTechnologyCybersecurity26 h ago

    A zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88779 with a CVSS score of 8.7, has been added to CISA's Known Exploited Vulnerabilities catalog amid reports of active exploitation. The flaw is a memory overflow in the SAML handler that can crash the appliance, disrupting VPN and SSO services for organizations using SAML SP or IdP configurations. Researchers warn it may bypass the previous patch. Fixed builds are 14.1-73.41 and 13.1-64.28, and administrators are urged to update immediately.

  4. 4
    Writers turn to vss prompts to restart writing after the electionβ–Όi think i should look up # vss here on Mastodon. when i joined bsky after the election, vss helped me get back into writMmastodonEnvironmentClimate51 d ago

    A writer says that joining Bluesky after the election, the very short story (vss) community helped them get back into writing, and they are now looking for similar prompt communities on Mastodon. They shared a story written for the prompt 'Displace' via Substack, hoping others will enjoy it.

  5. 5
    Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3●Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a paMmastodonTechnologyMobile23 d ago

    A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.

  6. 6
    High-severity flaw reported in NetScaler ADC and Gatewayβ–ΌCVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway https:// radar.offseq.com/threat/cve-20 26-88779-vulneraMmastodonTechnologyCybersecurity31 d ago

    A new vulnerability tracked as CVE-2026-88779 has been disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, with a high severity rating of 8.7 on the CVSS scale. The finding is circulating among cybersecurity professionals, who are monitoring the flaw for details on exploitation and the availability of patches from Citrix.

  7. 7
    Citrix NetScaler zero-day memory flaw added to CISA KEVβ—πŸ€– CVE-2026-88779 (CVSS 8.7): memory corruption (CWE-119) in Citrix NetScaler ADC/Gateway, reachable unauthenticated overMmastodonTechnologyCybersecurity110 h ago

    A high-severity memory corruption vulnerability, CVE-2026-88779 (CVSS 8.7), in Citrix NetScaler ADC and Gateway can be exploited unauthenticated over the network to cause denial of service. The flaw was attacked as a zero-day and has been added to CISA's Known Exploited Vulnerabilities catalog. Citrix has issued emergency fixes, and security teams are urged to patch immediately.

  8. 8
    Ciotau Joins VSS Capital Partners as Managing Director●Ciotau Joins VSS Capital Partners as Managing Director, AI and Value Creationβœ‰newsBusinessFinance11 min ago

    Ciotau has joined VSS Capital Partners as Managing Director, with a focus on artificial intelligence and value creation across the firm's portfolio. The appointment signals the private capital firm's growing emphasis on AI-driven operational improvement in its investments. Details on Ciotau's background and start date were not provided in the announcement.

  9. 9
    HKT48 and STU48 Launch Collaboration Sports Day Project●https://www. gotorola.com/554750/ HKT48vsSTU48γ‚³γƒ©γƒœδΌη”»ο½’γ‚‚γ—γ‚‚ε€§ι‹ε‹•δΌšο½£ε‰η·¨/坂口理子ο½₯ζΎε²‘θœζ‘˜ο½₯村重杏ε₯ˆvsηŸ³η”°εƒη©‚ο½₯甲斐心愛ο½₯η”°δΈ­ηš“ε­ # Entertainment # エンタパ # 村MmastodonCultureEntertainment021 h ago

    HKT48 and STU48 have teamed up for a collaboration project titled 'What If: Big Sports Festival', with a first part now available featuring members from both groups. The HKT48 side includes Riko Sakaguchi, Nao Matsuka and Anna Murashige, facing off against STU48's Chiho Ishida, Kokoa Kai and Hiroko Tanaka in the athletic competition format.

  10. 10
    Cross-site scripting flaw found in Greek Open eClass platformβ–ΌπŸš¨ EUVD-2024-55777 πŸ“Š Score: 5.4/10 (CVSS v3.1) πŸ“… Published: 2026-09-29 | Updated: 2026-09-30 πŸ“ Cross Site Scripting vulneMmastodonTechnologyCybersecurity04 d ago

    A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.

  11. 11
    Medium-severity vulnerability flagged in Burst Statistics WordPress pluginβ–ΌπŸš¨ EUVD-2026-91950 πŸ“Š Score: 4.3/10 (CVSS v3.1) πŸ“¦ Product: Burst Statistics – Simple WordPress Analytics (Google AnalyticsMmastodonTechnologyCybersecurity02 d ago

    A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.

  12. 12
    WordPress app builder plugin hit by stored XSS flawβ–ΌπŸš¨ EUVD-2026-91951 πŸ“Š Score: 5.4/10 (CVSS v3.1) πŸ“¦ Product: WPMobile.App – Android and iOS App Builder 🏒 Vendor: amauric πŸ“…MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App – Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.

  13. 13
    WPC Product Options plugin hit by stored XSS flawβ–ΌπŸš¨ EUVD-2026-91952 πŸ“Š Score: 7.2/10 (CVSS v3.1) πŸ“¦ Product: WPC Product Options for WooCommerce 🏒 Vendor: WPClever πŸ“… UpdateMmastodonTechnologyCybersecurity02 d ago

    A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

  14. 14
    Three unpatched critical flaws disclosed in LightLLMβ–ΌπŸš¨ LightLLM Mass Disclosure β€” 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) β€” unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI45 d ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  15. 15
    OpenTelemetry JavaScript instrumentation libraries flagged in new vulnerability advisoryβ–ΌπŸš¨ EUVD-2026-91788 πŸ“Š Score: 5.8/10 (CVSS v3.1) πŸ“¦ Product: instrumentation-cassandra-driver, instrumentation-pg, instrumenMmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, EUVD-2026-91788, has been catalogued affecting several OpenTelemetry JavaScript Contrib instrumentation packages, including instrumentation-cassandra-driver, instrumentation-pg and instrumentation-tedious. The flaw carries a CVSS v3.1 score of 5.8 out of 10 and was updated on 2 October 2026. Security teams monitoring dependencies in Node.js applications are likely reviewing whether their projects use the affected OpenTelemetry packages.

  16. 16
    GitLab patches critical CVSS 9.9 AI Gateway vulnerabilityβ—πŸš¨ GitLab AI Gateway vulnerability: CVE-2026-90970 GitLab has patched a critical **CVSS 9.9** vulnerability in its AI GatMmastodonTechnologyCybersecurity11 d ago

    GitLab has patched a critical vulnerability, CVE-2026-90970, rated CVSS 9.9, in its AI Gateway. The flaw allows an authenticated attacker to escape the prompt-template sandbox and execute arbitrary commands on self-hosted deployments. Security professionals are urging administrators to apply the update quickly and check whether their installations are affected.

  17. 17
    Newly published flaw hits AVEZ Electronics learning platformβ–ΌπŸš¨ EUVD-2026-91567 πŸ“Š Score: 6.5/10 (CVSS v3.1) πŸ“¦ Product: Learning Management System (LMS) 🏒 Vendor: AVEZ Electronics ComMmastodonTechnologyCybersecurity02 d ago

    A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.

  18. 18
    Low-severity directory traversal flaw patched in Trivy scannerβ–ΌπŸš¨ EUVD-2026-91789 πŸ“Š Score: 2.5/10 (CVSS v3.1) πŸ“¦ Product: trivy 🏒 Vendor: aquasec πŸ“… Updated: 2026-10-02 πŸ“ Trivy before 0.MmastodonTechnologyCybersecurity02 d ago

    A new vulnerability listing, EUVD-2026-91789, describes a directory traversal issue in Aqua Security's Trivy vulnerability scanner. Versions before 0.71.0 allow path traversal in Terraform filesystem functions that access pathnames above the scan root, with risk arising in misconfiguration scanning. The flaw carries a CVSS v3.1 score of 2.5, indicating low severity, and the advisory was updated on 2 October 2026. Users are advised to upgrade to 0.71.0 or later.

  19. 19
    YesWiki hit by nine vulnerabilities including SQL injection flawβ—πŸš¨ YesWiki 9 CVEs β€” CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requirMmastodonTechnologyCybersecurity11 d ago

    Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.

  20. 20
    High-severity SQL injection flaw reported in UTMStackβ–ΌπŸš¨ EUVD-2026-91790 πŸ“Š Score: 8.7/10 (CVSS v3.1) πŸ“¦ Product: UTMStack 🏒 Vendor: UTMStack πŸ“… Updated: 2026-10-02 πŸ“ UTMStack beMmastodonTechnologyCybersecurity02 d ago

    A newly catalogued vulnerability, EUVD-2026-91790, affects UTMStack versions before 11.2.16. The flaw is a SQL injection in the UtmAssetGroupService.searchQueryBuilder() component, allowing authenticated attackers to inject arbitrary SQL commands. The issue carries a CVSS v3.1 severity score of 8.7 out of 10, placing it in the high-severity range. The advisory record was updated on 2 October 2026, and users are expected to patch to version 11.2.16 or later.

  21. 21
    High-severity infinite loop flaw reported in Apache Thrift Python bindingsβ–ΌπŸš¨ EUVD-2026-91568 πŸ“Š Score: 8.2/10 (CVSS v3.1) πŸ“¦ Product: Apache Thrift 🏒 Vendor: Apache Software Foundation πŸ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.

  22. 22
    GitLab patches critical AI Gateway flaw allowing command executionβ—πŸ€– GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform accessMmastodonTechnologyCybersecurity12 d ago

    GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.

  23. 23
    New vulnerability disclosed in Dynamic Web Lab Team Manager pluginβ–ΌπŸš¨ EUVD-2025-30618 πŸ“Š Score: 5.3/10 (CVSS v3.1) πŸ“¦ Product: Team Manager 🏒 Vendor: Dynamic Web Lab πŸ“… Published: 2025-09-22MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.

  24. 24
    High-severity vulnerability disclosed in Apache Thrift Lua bindingsβ–ΌπŸš¨ EUVD-2026-91569 πŸ“Š Score: 8.2/10 (CVSS v3.1) πŸ“¦ Product: Apache Thrift 🏒 Vendor: Apache Software Foundation πŸ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.

  25. 25
    High-severity SQL injection flaw reported in HAVELSAN Sef chatbotβ–ΌπŸš¨ EUVD-2026-91329 πŸ“Š Score: 8.8/10 (CVSS v3.1) πŸ“¦ Product: Sef - AI Chatbot Platform 🏒 Vendor: Havelsan Inc. πŸ“… Updated: 20MmastodonTechnologyCybersecurity02 d ago

    A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.

  26. 26
    Kilo Code vulnerability lets local attackers run codeβ–ΌπŸš¨ EUVD-2026-89423 πŸ“Š Score: 8.4/10 (CVSS v3.1) πŸ“… Published: 2026-09-29 | Updated: 2026-09-30 πŸ“ An issue in Kilo Code befoMmastodonTechnologyCybersecurity04 d ago

    A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.

  27. 27
    Dell patches two CVSS 10.0 flaws in Kubernetes storage softwareβ—πŸ€– Dell patches two max-severity (CVSS 10.0) flaws in Container Storage Modules (CSM) Authorization v2.4.0, which connectMmastodonTechnologyCybersecurity12 d ago

    Dell has released Container Storage Modules Authorization v2.4.0 to fix two maximum-severity flaws, both rated CVSS 10.0, in the software that connects Dell storage arrays to Kubernetes clusters. The bugs stem from missing authentication, allowing unauthenticated remote attackers to retrieve backend admin credentials across all tenants. Security teams running Dell storage with Kubernetes are urged to update immediately, as the flaws expose sensitive credentials without requiring valid accounts.

  28. 28
    Critical vulnerability flagged in CISA's Malcolm network toolβ—πŸš¨ EUVD-2026-76738 πŸ“Š Score: 9.2/10 (CVSS v3.1) πŸ“¦ Product: Malcolm 🏒 Vendor: CISA πŸ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity02 d ago

    A high-severity vulnerability, EUVD-2026-76738, has been published for Malcolm, the open-source network traffic analysis toolkit distributed by CISA. The flaw, scored 9.2 out of 10 on the CVSS v3.1 scale, stems from an example environment-configuration file for a bundled inventory-management component that ships with a fixed, publicly known administrative password. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  29. 29
    Malcolm vulnerability EUVD-2026-76736 rated medium severityβ—πŸš¨ EUVD-2026-76736 πŸ“Š Score: 6.3/10 (CVSS v3.1) πŸ“¦ Product: Malcolm 🏒 Vendor: CISA πŸ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-76736 has been published for Malcolm, with a CVSS v3.1 score of 6.3 out of 10. According to the advisory, a prior update that raised a bundled HTTP client library to a version fixing known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  30. 30
    High-severity unquoted service path flaw reported in Remote Mouseβ—πŸš¨ EUVD-2026-3018 πŸ“Š Score: 8.5/10 (CVSS v3.1) πŸ“¦ Product: Remote Mouse 🏒 Vendor: Remotemouse πŸ“… Published: 2026-01-15 | UpdMmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2026-3018 has been published for Remote Mouse, the remote-control app by vendor Remotemouse. Version 4.002 contains an unquoted service path vulnerability, rated 8.5 out of 10 on the CVSS v3.1 scale, which can let a local attacker execute arbitrary code with elevated privileges. The entry was published on 15 January 2026 and updated on 1 October 2026. Users are advised to watch for a patched release from the vendor.

  31. 31
    Critical LightLLM flaw exposes AI servers to remote code executionβ—πŸš¨ CVE-2026-103041 β€” CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cacheMmastodonTechnologyCybersecurity05 d ago

    A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.

  32. 32
    Medium-Severity Flaw Reported in FluentForm WordPress Pluginβ–ΌπŸš¨ EUVD-2026-90761 πŸ“Š Score: 5.3/10 (CVSS v3.1) πŸ“¦ Product: FluentForm 🏒 Vendor: WP ManageNinja LLC πŸ“… Updated: 2026-10-01 πŸ“MmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2026-90761 has been published affecting FluentForm, the WordPress form plugin by WP ManageNinja LLC. The issue is classified as an Incorrect Behavior Order flaw with a CVSS v3.1 score of 5.3 out of 10, and can reportedly allow removal of important client functionality. Details were updated on 1 October 2026. Administrators running FluentForm are likely to check whether their installed version is affected and apply any available patch.

  33. 33
    Zitadel IAM flagged with D trust score over unpatched flaws●Zitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know youMmastodonTechnologyCybersecurity02 d ago

    Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.

  34. 34
    Critical 10/10 vulnerability disclosed in Tenda routersβ—πŸš¨ EUVD-2026-91570 πŸ“Š Score: 10.0/10 (CVSS v3.1) πŸ“¦ Product: HG9, HG7, HG10 🏒 Vendor: Tenda πŸ“… Updated: 2026-10-02 πŸ“ A securMmastodonTechnologyCybersecurity02 d ago

    A maximum-severity security flaw, tracked as EUVD-2026-91570 with a CVSS score of 10.0, has been disclosed in Tenda HG7, HG9 and HG10 routers running the 300001138_en_xpon firmware. The vulnerability lies in the boaGetVar function in the /boaform/formLoopBack file. The advisory was updated on 2 October 2026, and security watchers are sharing the disclosure.

  35. 35
    High-severity XML flaw flagged in Apache Camel Quarkusβ–ΌπŸš¨ EUVD-2026-90762 πŸ“Š Score: 8.6/10 (CVSS v3.1) πŸ“¦ Product: Apache Camel Quarkus, Apache Camel Quarkus 🏒 Vendor: Apache SofMmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2026-90762 has been recorded for Apache Camel Quarkus, the Apache Software Foundation's Quarkus extensions for Camel. The flaw, rated 8.6 out of 10 under CVSS v3.1, involves improper restriction of XML external entity references in the XSLT support extension (camel-quarkus-support-xalan). Such issues can allow attackers to read files or make requests from affected systems. The record was updated on 1 October 2026, and security teams are being urged to check whether their deployments use the affected extension.

  36. 36
    Keycloak Kerberos flaw lets network attackers hijack accounts●CVE-2026-95503 Keycloak Kerberos auth bypass, CVSS 6.8. Unpatched. Same-network attacker can spoof the KDC and take overMmastodonTechnologyCybersecurity02 d ago

    A newly disclosed vulnerability, CVE-2026-95503, affects Keycloak's Kerberos authentication and carries a CVSS score of 6.8. It remains unpatched. An attacker on the same network can spoof the Kerberos Key Distribution Center and take over user accounts. Security commentators urge administrators to isolate Kerberos traffic or stop using password authentication without SPNEGO protection until a fix is released.

  37. 37
    High-severity vulnerability disclosed in Apache Thrift Lua libraryβ—πŸš¨ EUVD-2026-91330 πŸ“Š Score: 8.7/10 (CVSS v3.1) πŸ“¦ Product: Apache Thrift 🏒 Vendor: Apache Software Foundation πŸ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.

  38. 38
    ArgusMonitor Driver Vulnerability Flagged With Medium Severityβ–ΌπŸš¨ EUVD-2026-89424 πŸ“Š Score: 5.3/10 (CVSS v3.1) πŸ“… Published: 2026-09-29 | Updated: 2026-09-30 πŸ“ Improper Access Control inMmastodonTechnologyCybersecurity04 d ago

    A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.

  39. 39
    New security vulnerability disclosed in Red Hat Enterprise Linux productsβ–ΌπŸš¨ EUVD-2023-24169 πŸ“Š Score: 7.0/10 (CVSS v3.1) πŸ“¦ Product: Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat VMmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2023-24169 has been published affecting several Red Hat products, including Red Hat Enterprise Linux 8.6 and 8.8 Extended Update Support and Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. The flaw carries a CVSS v3.1 severity score of 7.0 out of 10, placing it in the high-severity range. Administrators running the affected versions are being advised to review the advisory and apply patches.

  40. 40
    SSRF Vulnerability Disclosed in HAVELSAN Sef AI Chatbot Platformβ—πŸš¨ EUVD-2026-91323 πŸ“Š Score: 4.9/10 (CVSS v3.1) πŸ“¦ Product: Sef - AI Chatbot Platform 🏒 Vendor: Havelsan Inc. πŸ“… Updated: 20MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91323 with a CVSS v3.1 score of 4.9, has been recorded for the Sef AI Chatbot Platform developed by Turkish defence technology company HAVELSAN Inc. The flaw is a server-side request forgery (SSRF) issue, which can allow an attacker to make the server send arbitrary requests. The advisory was updated on 2 October 2026; affected versions have not been fully detailed in the published record.