News
Unauthenticated Takeover in Label Software BarTender (CVE-2026-25550): Legacy 2010/2016/2019 at Risk
SecurityInfrastructure
BarTender, the label and barcode printing software widely used in factories, warehouses and logistics, has a 9.8-severity flaw (CVE-2026-25550) in its legacy 2010/2016/2019 versions. An attacker can take over the PC remotely with no login and run code at the highest privilege. Block the service and migrate.
2026.06.0527 views
News
Plex Companion Tautulli Hit by Five Flaws (CVE-2026-43986 and More): Update to v2.17.1
InfrastructureDevelopmentSecurity
Tautulli, the popular dashboard that tracks viewing on the Plex media server, has five vulnerabilities including a 9.9-severity flaw. Some paths work without logging in, and chained together they lead to admin-panel takeover or code execution on your server. Update to v2.17.1.
2026.06.0528 views
News
Critical Takeover Flaw in OpenStack Mistral: CVE-2026-41283 Lets Any Logged-In User Run Code
DevelopmentSecurityInfrastructure
CVE-2026-41283: a 9.9-severity flaw in OpenStack Mistral lets any logged-in user run arbitrary code and steal cloud-wide service credentials. Patch now.
2026.06.0434 views
News Updated 4 days ago
Magento Mirasvit Cache Warmer Takeover Flaw, Fixed in 1.11.12+
DevelopmentInfrastructureSecurity
A Magento extension used by online stores worldwide has a critical flaw (CVE-2026-45247, CVSS 9.8) that lets attackers take over servers without logging in. Real attacks have already begun, risking theft of shoppers' credit card data. Affected stores must update to 1.11.12 now.
2026.06.045 views
News Updated 4 days ago
Apache MINA Takeover Flaw: The Safe Versions Are 2.2.8, 2.1.15, and 2.0.31
SecurityDevelopmentInfrastructure
Apache MINA, the Java networking library behind many server apps, has a critical flaw (CVE-2026-47065, CVSS 9.8) that lets attackers take over servers without logging in. It is the third bypass of earlier fixes—update to 2.2.8, 2.1.13, or 2.0.29 now.
2026.06.0318 views
News Updated 4 days ago
authentik Identity Platform: 4 Flaws, and the Releases That Fix Them
InfrastructureGlobal CompaniesSecurity
Four serious vulnerabilities have been found in authentik, the identity platform widely used for single sign-on. The worst lets an unauthenticated attacker skip an authentication step by sending empty data and log in as someone else (CVE-2026-49448, CVSS 9.8). Here are the affected versions, the patched releases to update to now, and how to check.
2026.06.0316 views
News Updated 4 days ago
Linux container escape flaw explained: safe on kernel 5.17 and later
InfrastructureSecurityLinux
Linux cgroups v1 flaw CVE-2022-0492 is being exploited and CISA added it to KEV. A missing permission check on release_agent enables container escape and privilege escalation. Escape needs conditions like privileged containers. Update to kernel 5.17+ and harden.
2026.06.0337 views
News
Flaw in Amazon's AI dev tool Kiro, CVE-2026-10591: open a folder, run code
SecurityDevelopmentAI
Amazon Kiro flaw CVE-2026-10591 (CVSS 8.8): the AI's file-write tool can write to .vscode/tasks.json, auto-running an attacker's command when the folder opens. Prompt injection is the trigger. Update to Kiro 0.11 or later.
2026.06.0316 views
News
Five flaws in enterprise CMS Sitefinity, unauthenticated data exposure: CVE-2026-7198 and more
SecurityInfrastructureGlobal Companies
Five flaws disclosed in enterprise CMS Progress Sitefinity: unauthenticated access to private content (CVE-2026-7198, 9.8) and conditional plain-text credential exposure (CVE-2026-7312, 10.0). From the maker of MOVEit. Conditions and fixed builds by branch.
2026.06.0314 views
News Updated 4 days ago
OpenShift Traffic-Hijacking Flaw: Affected Versions and the Fix
InfrastructureSecurityGlobal Companies
OpenShift flaw CVE-2026-1784 (CVSS 8.8): weak Route spec.path validation lets a low-privilege user inject the shared router's HAProxy config and hijack other tenants' traffic. Affected: OpenShift Container Platform 4. Patch and audit route permissions.
2026.06.0217 views
News
WordPress 'Kirki' flaw CVE-2026-8206 now exploited to hijack admins on 500k sites
Global CompaniesDevelopmentSecurity
Attacks are now hitting CVE-2026-8206 in Kirki, a WordPress plugin on 500,000+ sites. Wordfence blocked 222+ attempts in 24 hours. Unauthenticated attackers can hijack admin accounts — update to 6.0.7 now.
2026.06.0217 views
News
Flaw in two TP-Link Wi-Fi routers risks full takeover: CVE-2026-5509
InfrastructureGlobal CompaniesSecurity
TP-Link's Archer BE450 and BE7200 Wi-Fi routers have a flaw (CVE-2026-5509): an admin-logged-in attacker can take over the router. Update the firmware now.
2026.06.0215 views