News Updated 7 days ago
12 flaws in baserCMS, only one is traceable (CVE-2026-65875)
DevelopmentSecurity
baserCMS disclosed 12 flaws on July 30, 2026, three rated Critical. Eleven cannot be looked up by number, and Dependabot warns about none of them.
2026.08.037 views
News Updated 7 days ago
8 flaws in the chip inside four phones sold in Japan (CVE-2026-21548)
SecurityMobile
UNISOC disclosed eight chip flaws on August 1, 2026. The T8100 ships in four phones sold in Japan. All eight only cut connectivity, but no patch date exists.
2026.08.0314 views
News Updated 7 days ago
27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)
DevelopmentSecurity
27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.
2026.08.039 views
News Updated 7 days ago
27 WordPress plugin flaws: CVE-2026-15383 hits a Japan-made plugin
SecurityDevelopmentJapanese Companies
27 WordPress plugin flaws went public Aug 3, 2026. One hits a Japan-made plugin on 9,000 sites: any visitor can plant script that runs in the admin dashboard. It was quietly fixed July 31.
2026.08.0312 views
News
Cybozu Garoon CVE-2026-57279 affects only 6.17.0 and 6.17.1
SecurityJapanese Companies
A cross-site scripting flaw in Cybozu Garoon affects just two package-edition releases, 6.17.0 and 6.17.1. Fixed in 6.17.2. Here is how to tell in one check.
2026.08.039 views
News Updated 5 days ago
Both N-central Auth Bypass Flaws Now Exploited; Patch to 2026.3.1.7
InfrastructureSecurity
N-able N-central has a login bypass that hands over administrator accounts. The vendor rates it as actively attacked and has published indicators of compromise. Fixed in build 2026.3.1.7.
2026.08.0317 views
News
Sharp printer flaw CVE-2026-60011 affects 164 models, 78 get no fix
SecurityJapanese Companies
A flaw in 164 Sharp multifunction printer models lets stored scans be read without logging in. 78 models are past firmware support and get no fix at all.
2026.08.038 views
News
Transformers path traversal writes files anywhere (CVE-2026-9856)
SecurityAIDevelopment
Loading and saving a crafted Hugging Face model lets an attacker write files outside its folder. NVD's affected range is wrong — upgrade to 5.10.1 or later.
2026.08.0312 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
DevelopmentInfrastructureSecurity
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0312 views
News
Better Auth and 4 more: 11 CVEs, all already fixed (CVE-2025-71399)
SecurityDevelopment
Five projects got 11 CVE numbers on August 2, but none is a new flaw — every fix shipped between November 2025 and July 2026. Only FreeRDP needs action.
2026.08.0213 views
News
27 WordPress flaws at once, six with no patch: CVE-2026-16261
SecurityDevelopment
27 WordPress plugin and theme flaws landed on Aug 2, 2026. Six have no fix, and all six were pulled from the official directory, so no update notice appears.
2026.08.0221 views
News
Forged Apple login takes over WordPress admin: CVE-2026-8457 +2 flaws
DevelopmentSecurity
Three WordPress plugin flaws went public on Aug 1, 2026. A forged 'Sign in with Apple' token can make anyone an administrator; two others let visitors read server files.
2026.08.0213 views