News Updated today
Perfect-10 unauthenticated takeover in PrestaShop's search module: CVE-2026-54159 — update ps_facetedsearch to 4.0.4
SecurityDevelopment
PrestaShop, the popular free software for building online stores, has a maximum-severity (10.0) flaw in its standard filtered-search feature. Tracked as CVE-2026-54159, a single crafted URL can take over the shop and server with no login. The affected module is Faceted Search 3.0.0-4.0.3; update to 4.0.4.
2026.07.183 views
News Updated today
Two site-takeover flaws in WordPress core: CVE-2026-60137 and CVE-2026-63030 — update now
DevelopmentSecurity
WordPress, used by about 40% of all websites, has two database-tampering flaws (SQL injection) in its core. Tracked as CVE-2026-60137 and CVE-2026-63030, when chained they can let attackers take over a site with no login. Fixes 6.8.6, 6.9.5, and 7.0.2 shipped and auto-updates were force-pushed. Here's how to confirm your site is already fixed.
2026.07.189 views
News Updated today
Just opening a repo in Cursor can hijack a Windows PC: CVE-2026-63093, and there's still no official fix
DevelopmentAISecurity
A flaw in the Windows version of Cursor, the AI code editor used by over 7 million developers, can let attackers run code on your PC just by getting you to open a booby-trapped repository. Tracked as CVE-2026-63093 (severity 8.8), it has no published fixed version — Cursor calls it out of scope, so users must protect themselves for now.
2026.07.182 views
News Updated today
Takeover-enabling flaws in the popular self-hosted AI agent OpenClaw, plus no-login impersonation in its checker: CVE-2026-62241 and 9 more — update now
AISecurity
A wave of vulnerabilities has hit OpenClaw, the popular self-hosted AI agent used worldwide, letting people do things they shouldn't. Its companion security-checking tool has a critical (9.1) flaw allowing user impersonation with no login. Fixed versions are out: update OpenClaw to 2026.6.9+ and the checker to 0.7.5+. Here are the affected products and how to fix them.
2026.07.171 views
News Updated yesterday
Account-takeover flaw in Zoom's Windows apps, no login or interaction needed: CVE-2026-53412 — update to the latest version
Global CompaniesSecurity
A critical flaw, CVE-2026-53412 (CVSS 9.8), was found in the Windows version of the video-conferencing app Zoom. With no login and no user interaction, an account can be taken over over the network. The affected products are the Windows desktop, VDI, and developer SDK versions; Mac and mobile are not affected. Fixed versions are out, so updating to the latest is recommended.
2026.07.171 views
News Updated yesterday
Document-to-AI tool Docling hit by a string of flaws: crafted documents or URLs can leak internal information — CVE-2026-44023 and 7 more, update now
AISecurity
Docling, a popular tool for feeding PDFs and Word files into AI, has eight flaws led by CVE-2026-44023 (severity 8.6) that can be used to steal internal files and information via crafted documents or URLs. They include SSRF and XXE and affect setups that process untrusted data. Updating docling-core to 2.74.1 and the main docling to 2.94.0 or later fixes them. No real-world attacks confirmed.
2026.07.172 views
News Updated yesterday
WireGuard Easy (wg-easy) flaw lets attackers steal VPN connection details — dangerous if the admin panel is exposed: CVE-2026-63089, no stable fix released yet
SecurityInfrastructure
A critical flaw, CVE-2026-63089 (CVSS 9.3), was found in WireGuard Easy (wg-easy), a popular tool for standing up a VPN with no fiddly setup. The token on its single-use share link has only 1,000 possibilities and no attempt limit, so if the admin panel is exposed to the internet, attackers can steal VPN connection settings without logging in. No stable fix has been released yet; for now you must keep the admin panel off the internet.
2026.07.171 views
News Updated yesterday
Grafana OnCall (open-source) can be fully taken over without login — and no patch is coming: CVE-2026-63087, stop using it and migrate
InfrastructureSecurity
A critical flaw, CVE-2026-63087 (CVSS 9.8), lets anyone take over Grafana OnCall (the open-source on-call/alerting tool) completely without logging in. The open-source edition is already end-of-life, so no patch is coming. All versions are affected; block the management port now and migrate to the supported successor.
2026.07.175 views
News Updated yesterday
Critical flaw in a tool bundled with Ubuntu (CVE-2026-11386): a spoofed server could sneak in malicious software — update now
SecurityLinux
A critical flaw, CVE-2026-11386 (CVSS 9.0), was found in ubuntu-pro-client, a tool bundled with Ubuntu and used on servers worldwide. Loose validation of the contract server's response lets a spoofed server rewrite where software is fetched from and plant malicious packages. All supported LTS releases are affected; a normal security update applies the fix.
2026.07.162 views
News Updated yesterday
Critical flaw in Spring Authorization Server (CVE-2026-22752): a crafted client registration can lead to impersonation and data theft — update to 7.0.5 / 1.5.7
SecurityDevelopment
A critical flaw, CVE-2026-22752 (CVSS 9.6), has been disclosed in Spring Authorization Server, the Java foundation used for login integration in enterprise systems. When Dynamic Client Registration is enabled, crafted data can lead to impersonation, privilege escalation, and internal probing. The fix is to update to 7.0.5 or 1.5.7, or to disable dynamic registration.
2026.07.161 views
News Updated yesterday
Three popular WordPress plugins hit by admin-takeover flaws, including a translation tool on 1M+ sites (CVE-2026-15005 and more) — update now (July 16, 2026)
SecurityDevelopment
On July 16, 2026, three popular WordPress plugins were disclosed to carry serious takeover flaws: the translation tool Loco Translate (1M+ installs), the phone-number login plugin Digits, and the funnel builder WPFunnels. All three can let an attacker impersonate an administrator, rated 8.8 out of 10. Updating each plugin to its latest version resolves the risk.
2026.07.162 views
News Updated yesterday
Credit cards went down across Japan on July 16: convenience stores and Suica top-ups hit — the cause was an international card network outage
MobileJapanese CompaniesInfrastructure
On the morning of July 16, 2026, credit card payments briefly failed at convenience stores, drugstores, and station ticket machines across Japan, and Mobile Suica and PASMO top-ups were hit too. The cause was a failure in the international payment network linking card companies; it recovered by midday. Cash and already-charged balances still worked. Here is what happened, in order.
2026.07.168 views