News Updated today
Three Galaxy flaws exploitable with no user action, fixed in the July update (CVE-2026-21047)
SecurityMobile
Samsung's July 2026 Galaxy update fixes three flaws exploitable with no user action. Two sit in the same image codec that spyware exploited last year.
2026.07.281 views
News Updated today
RabbitMQ can be taken down with no login, and no fixed release yet (CVE-2026-59248)
SecurityInfrastructure
An unauthenticated attacker can exhaust memory and take RabbitMQ down via its management ports. Every released version including 4.3.4 is affected, and no fixed RabbitMQ release exists yet.
2026.07.283 views
News Updated today
Three flaws across seven ELECOM Wi-Fi routers and access points (CVE-2026-59764)
SecurityJapanese Companies
Three flaws in seven ELECOM Wi-Fi routers and access points, July 28 2026. Fixed firmware shipped in May and June; the consumer models auto-update by default.
2026.07.284 views
News Updated today
Bouncy Castle can leak a private key through timing: CVE-2024-14041, fixed in 1.78
SecurityDevelopment
A timing flaw in Bouncy Castle's post-quantum ML-KEM code can leak a private key. It was already fixed in 1.78 (April 2024); only versions 1.73 to 1.77 are exposed.
2026.07.284 views
News Updated today
3DEXPERIENCE hit by a perfect 10.0 flaw: CVE-2026-11756 targets the designer's PC
Global CompaniesSecurity
A perfect 10.0 flaw in 3DEXPERIENCE: CVE-2026-11756 needs no login, hits the Station Launcher App on engineers' PCs, and the fixed build is not public.
2026.07.283 views
News Updated today
Eighteen WordPress plugin flaws, two with no fix at all (CVE-2026-15014)
DevelopmentSecurity
Eighteen WordPress plugin flaws, July 28 2026 — eleven need no login and two have no fix at all. Bookly's published affected range is wrong: 27.7 is still exploitable.
2026.07.285 views
News Updated yesterday
vBulletin Forum Software Hit by Critical Flaw CVE-2026-61511: Unauthenticated Server Takeover
SecurityDevelopment
vBulletin, the forum software used by community sites worldwide, has a flaw (CVE-2026-61511, severity 9.8) that lets anyone take over the server without logging in, and it is already being exploited. Versions up to 5.7.5 and 6.2.1 are affected; the fix is to update to 6.2.2 immediately.
2026.07.2813 views
News Updated yesterday
Apache Thrift Hit by 5 Vulnerabilities: Traffic Eavesdropping and Service Outage Risks (CVE-2026-48144, CVSS 9.1)—Update to 0.24.0
SecurityDevelopmentInfrastructure
Apache Thrift, the communication framework behind many systems, has five vulnerabilities that could let attackers eavesdrop on or tamper with encrypted traffic and take services down. The worst, CVE-2026-48144, scores 9.1 of 10. Impact varies by language binding; the fix is updating to 0.24.0.
2026.07.275 views
News Updated 5 days ago
Red Hat OpenShift AI: in-cluster pods can impersonate any user (CVE-2026-16745)
InfrastructureAISecurity
A flaw in Red Hat OpenShift AI (CVE-2026-16745, CVSS 8.8) lets an in-cluster attacker impersonate any user, including admins. Versions 2.25/3.3/3.4 affected; fixed in 3.5.
2026.07.2312 views
News Updated 5 days ago
Four WordPress plugins hit by critical site-takeover flaws (July 23)
SecurityDevelopment
Four WordPress plugins have site-takeover flaws; three are a critical 9.8 needing no login (GoDAM, a helpdesk plugin, an AI MCP connector, MDJM). Update now.
2026.07.239 views
News Updated 5 days ago
Fastjson RCE (CVE-2026-16723) puts Spring Boot apps at risk — act now
SecurityDevelopment
Crafted data can hijack servers running old Fastjson 1.2.68-1.2.83 (CVE-2026-16723, CVSS 9.0). Only some Spring Boot apps are affected, and there is no 1.x fix.
2026.07.2325 views
News Updated 5 days ago
Free Backup Tool 'Duplicati' Has an Admin-Takeover Flaw (CVE-2026-16157) — Only a Risk for Non-Default Install Folders
SecurityDevelopment
The Windows edition of Duplicati, a widely used free backup tool, has a flaw that could let someone seize the PC's most powerful (administrator) account. But it is only dangerous if you installed it in a non-default folder; a standard install is barely affected. Exploitation requires the ability to operate the machine, and the fix is to reinstall to the default folder or tighten the permissions.
2026.07.237 views