News
ACF Extended Admin-Hijack Returns 4 Months Later: CVE-2026-8809, Fix 0.9.2.6
DevelopmentSecurity
CVE-2026-8809 (CVSS 9.8) in the WordPress plugin Advanced Custom Fields: Extended (ACF Extended) lets unauthenticated attackers create administrator accounts. All ≤ 0.9.2.5 vulnerable, fixed in 0.9.2.6. 100,000+ sites affected. The second same-shape admin-hijack bug in ACFE in four months. Shipped silently — official changelog says only 'CSS tweaks'.
2026.05.2911 views
News Updated 4 days ago
Oracle Monthly CSPU and the ORDS CVSS 10.0: Current Status and Safe Versions
Global CompaniesInfrastructureSecurity
On May 28, 2026, Oracle switched its quarterly CPU to a monthly CSPU. The first wave shipped 35 patches, including a CVSS 10.0 in Oracle REST Data Services (CVE-2026-46840), 12 for E-Business Suite, 3 for Database, and 1 for Hospitality OPERA 5. The Cl0p E-Business Suite zero-day campaign is the backdrop.
2026.05.2948 views
News
vLLM Ignores --trust-remote-code=False: Third RCE, CVE-2026-4944
SecurityDevelopmentAI
vLLM silently overrides your --trust-remote-code=False via hardcoded True in two model files (nemotron_vl.py, kimi_k25.py). Malicious HuggingFace repos can trigger RCE. Fixed in vLLM 0.18.0. The third bypass in the series.
2026.05.2931 views
News
Zed Editor RCE Fix (CVE-2026-44461–44466): Update to 0.229.0 — Opening a Malicious Repo Runs Code on Your Machine
DevelopmentAISecurity
Opening a malicious repo in the Zed editor runs arbitrary code on your machine. CVE-2026-44466 (CVSS 8.6) plus 3 more RCEs hit versions before 0.227.1/0.229.0. The fix is 0.229.0 — update now.
2026.05.2976 views
News
TinyMCE Stored XSS Fix (CVE-2026-47759–47762): Patch to 8.5.1 / 7.9.3 / 5.11.1 — Editors Can Hijack Admin
DevelopmentSecurity
TinyMCE ships four simultaneous stored-XSS fixes (CVE-2026-47759 through 47762, all CVSS 8.7) across data-mce-* attributes, nested SVGs, the media plugin, and mce:protected comments. Patch to 8.5.1, 7.9.3, or 5.11.1 LTS now.
2026.05.2970 views
News
Japan's 'Kokkai-Map' Goes Viral, Built Solo with Claude Haiku 4.5
DevelopmentAI
Kokkai-Map, a Japanese politician tracker built solo by construction-firm owner Shinnosuke Nakajima with Claude Haiku 4.5 and the National Diet Library API, went viral on May 27, 2026, surviving a 26-minute server outage to hit 21,000 X followers.
2026.05.2920 views
News Updated 4 days ago
Samba Vulnerabilities: Safe on 4.22.10/4.23.8/4.24.3+, Default Configs Unaffected
InfrastructureLinuxSecurity
Samba file servers and classic domain controllers are exposed to unauthenticated RCE via CVE-2026-4408 (CVSS 9.0). The %u substitution in check password script passes the client-controlled username to the shell without escaping metacharacters, allowing arbitrary root command execution over SAMR. Fixed in Samba 4.22.10, 4.23.8, and 4.24.3.
2026.05.2843 views
News Updated 4 days ago
Jupyter Server's Login Page Can Be Abused for Phishing: Update to 2.20.0
SecurityAIDevelopment
CVE-2025-61669 (CVSS 6.1) lets attackers craft a Jupyter Server login URL that bounces researchers and data scientists to any external site, turning the familiar Jupyter login page into a phishing launcher. Jupyter Server 2.17.0 and earlier are affected, fixed in 2.18.0. JupyterLab and Notebook 7 inherit the flaw via their backend. Reported by Noriaki Iwasaki of Japan's Cyber Defense Institute.
2026.05.2811 views
News
Goobi Viewer Hit by Unauthenticated CVE-2026-45083: Digital Archives At Risk
SecurityInfrastructureDevelopment
CVE-2026-45083 (CVSS 9.8) lets unauthenticated network clients send arbitrary Solr streaming expressions to Goobi viewer, the digital archive platform widely used by libraries, museums and research institutions. Versions 4.8.0 through 26.04.0 are affected; the broken endpoint was removed in 26.04.1.
2026.05.2819 views
News
Two Unauthenticated RCEs in Pi.Alert: CVE-2026-44887 / 44888 Hit Home Network Watchers
SecurityLinuxInfrastructure
Pi.Alert, the home/SOHO Wi-Fi and LAN intruder detector, ships with two unauthenticated RCE flaws (CVE-2026-44887/44888, both CVSS 9.8). Web protection is disabled by default, letting any attacker write Python code into pialert.conf which the scan daemon then loads via exec(). Patched in the 2026-05-07 release.
2026.05.2820 views
News
Three Critical Flaws Hit Gladinet Triofox: CVE-2026-8362 / 8363 / 8364, Enterprise File Sharing At Risk
Global CompaniesSecurityInfrastructure
Tenable Research disclosed three critical unauthenticated RCE vulnerabilities (CVE-2026-8362/8363/8364, all CVSS 9.8) in Gladinet Triofox enterprise file sharing on May 27, 2026. Versions up to 17.1.10488.57063 are vulnerable; fixed in 17.3.10565.57509.
2026.05.2832 views
News
Budibase Hit by Five Critical Authz Flaws: CVE-2026-46425 et al., Update to v3.39.0
AISecurityDevelopment
Five critical authorization and SSRF vulnerabilities in the Budibase low-code platform (CVE-2026-46425/48150/45716/45717/48153, CVSS 9.9 to 8.5) were disclosed on May 27, 2026. Issues range from SCIM router bypass to tenant-wide privilege escalation to global admin. Fixed in v3.39.0.
2026.05.2819 views