News
New Langroid server-takeover flaw CVE-2026-54769 (CVSS 10.0): AI-written code gives unauth RCE — update to 0.65.2
AISecurityDevelopment
Langroid's SQLChatAgent runs AI-generated SQL unchecked (CVE-2026-25879, CVSS 9.8): prompt injection can reach DB-host RCE. Update to v0.63.0; least privilege.
2026.06.0217 views
News
Cloud Foundry UAA leaks its private key: CVE-2026-40965 (CVSS 10.0)
SecurityGlobal CompaniesInfrastructure
Cloud Foundry UAA exposes its EC private key via a public page (CVE-2026-40965, CVSS 10.0): token forgery risk. Only EC configs affected. Patch and rotate keys.
2026.06.0226 views
News Updated 4 days ago
Oracle WebLogic vulnerabilities: exploited flaw and latest patch status
InfrastructureSecurityGlobal Companies
CISA added Oracle WebLogic CVE-2024-21182 to its KEV catalog as exploited in the wild. Data can be read without login; the fix shipped July 2024. What to check now.
2026.06.0236 views
News
Four WordPress plugins hit with critical takeover flaws: CVE-2026-48866 and 3 more
Global CompaniesSecurityDevelopment
Four popular WordPress plugins were hit with critical flaws (up to CVSS 9.8): file deletion in Gravity Forms (CVE-2026-48866) and unauthenticated site takeover in Contest Gallery, wpForo and AIWU. Who's affected and what to update now.
2026.06.0233 views
News
CATIA design-data server hijacked without login: CVE-2026-7858 (and DELMIA XSS CVE-2026-9024)
SecurityInfrastructureGlobal Companies
Dassault disclosed CVE-2026-7858 (CVSS 9.8): an unauthenticated takeover of the CATIA design-data server Teamwork Cloud, plus a DELMIA XSS flaw. Who's affected and what to do.
2026.06.0130 views
News Updated 4 days ago
Major Vulnerabilities Hitting Japanese Enterprises in 2026: Status and Fixes
SecurityJapanese CompaniesInfrastructure
In H1 2026, serious vulnerabilities hit products Japanese firms rely on, from Fujitsu and NEC to Microsoft and Oracle. A cross-vendor hub for in-house IT teams.
2026.06.0130 views
News
CVE-2026-48188: OTRS Helpdesk Auth Bypass, No Login Needed (Fix 2026.4.X)
PrivacySecurity
CVE-2026-48188 (CVSS 9.1) lets attackers break into the OTRS helpdesk with no login via unauthenticated SQL injection, but only when MySQL/MariaDB runs in NO_BACKSLASH_ESCAPES mode. Fixed in OTRS 2026.4.X; the end-of-life Community Edition 6.0.x is most at risk.
2026.06.0140 views
News Updated 4 days ago
Fujitsu ServerView Agents Privilege Escalation: Fixed in V11.70.06 and Later
SecurityJapanese CompaniesInfrastructure
ServerView Agents for Windows, the PRIMERGY management software from Fsas Technologies (Fujitsu), has two privilege-escalation flaws: CVE-2026-27788 (CWE-732) and CVE-2026-32325 (CWE-268), CVSS 8.5. Anyone who can log in seizes Windows SYSTEM privileges; V11.60.04 and earlier are affected. Update to the latest version.
2026.06.0138 views
News
Casdoor SSO Auth Bypass (CVE-2026-9090 to 9098): No Patch Yet, Here Is How to Lock It Down Now
SecurityPrivacy
If your organization self-hosts Casdoor as its SSO login server, you are affected: CERT/CC disclosed nine authentication-bypass flaws (CVE-2026-9090 to 9098, VU#780781) in v2.362.0 and earlier that let an attacker log in as any user or admin. There is still no patch as of June 22, 2026, so the fix is operational: restrict the IdPs Casdoor accepts to trusted ones and audit your accounts now.
2026.06.0144 views
News
OpenCATS flaw exposes the entire candidate database (CVE-2026-49489)
SecurityPrivacy
OpenCATS (<=0.9.7.4) has SQL injection flaw CVE-2026-49489 (CVSS 8.5): any logged-in user can dump the candidate database. A public exploit exists; no fix yet.
2026.05.3120 views
News Updated 4 days ago
PAN-OS GlobalProtect Authentication Bypass: Safe Versions and Exploitation Status
SecurityInfrastructure
CVE-2026-0257 is an authentication bypass in Palo Alto Networks' GlobalProtect VPN (PAN-OS) that lets attackers forge cookies and connect to internal networks without valid credentials. Already exploited in the wild; CISA added it to KEV with a June 1 deadline. Affected: PAN-OS 10.2 / 11.1 / 11.2 / 12.1. Full affected-and-fixed version table and indicators of compromise inside.
2026.05.3031 views
News
Mautic Hit by Twig-Theme SSTI RCE: CVE-2026-9558, Bundled May Patch Fixes 7 CVEs
DevelopmentSecurity
CVE-2026-9558 (CVSS 9.9) in Mautic, the open-source marketing automation platform, lets authenticated users with theme-upload permission execute arbitrary code via Twig SSTI: themes were rendered without a sandbox. Fixed in 7.1.2 / 6.0.9 / 5.2.11 / 4.4.20 (ELTS), with six more CVEs (SQLi, SSRF, path traversal, authz bypass, stored XSS x2) shipped in the same May 28, 2026 release. ~18,000 live sites and a growing Japanese B2B marketing footprint backed by Acquia Japan.
2026.05.2926 views