News
Flaw in Amazon's AI dev tool Kiro, CVE-2026-10591: open a folder, run code
AISecurityDevelopment
Amazon Kiro flaw CVE-2026-10591 (CVSS 8.8): the AI's file-write tool can write to .vscode/tasks.json, auto-running an attacker's command when the folder opens. Prompt injection is the trigger. Update to Kiro 0.11 or later.
2026.06.0345 views
News
Five flaws in enterprise CMS Sitefinity, unauthenticated data exposure: CVE-2026-7198 and more
SecurityInfrastructureGlobal Companies
Five flaws disclosed in enterprise CMS Progress Sitefinity: unauthenticated access to private content (CVE-2026-7198, 9.8) and conditional plain-text credential exposure (CVE-2026-7312, 10.0). From the maker of MOVEit. Conditions and fixed builds by branch.
2026.06.0344 views
News
OpenShift Traffic-Hijacking Flaw: Affected Versions and the Fix
InfrastructureSecurityGlobal Companies
OpenShift flaw CVE-2026-1784 (CVSS 8.8): weak Route spec.path validation lets a low-privilege user inject the shared router's HAProxy config and hijack other tenants' traffic. Affected: OpenShift Container Platform 4. Patch and audit route permissions.
2026.06.0237 views
News
WordPress 'Kirki' flaw CVE-2026-8206 now exploited to hijack admins on 500k sites
Global CompaniesDevelopmentSecurity
Attacks are now hitting CVE-2026-8206 in Kirki, a WordPress plugin on 500,000+ sites. Wordfence blocked 222+ attempts in 24 hours. Unauthenticated attackers can hijack admin accounts — update to 6.0.7 now.
2026.06.0234 views
News
Flaw in two TP-Link Wi-Fi routers risks full takeover: CVE-2026-5509
InfrastructureGlobal CompaniesSecurity
TP-Link's Archer BE450 and BE7200 Wi-Fi routers have a flaw (CVE-2026-5509): an admin-logged-in attacker can take over the router. Update the firmware now.
2026.06.0248 views
News
New Langroid server-takeover flaw CVE-2026-54769 (CVSS 10.0): AI-written code gives unauth RCE — update to 0.65.2
AISecurityDevelopment
Langroid's SQLChatAgent runs AI-generated SQL unchecked (CVE-2026-25879, CVSS 9.8): prompt injection can reach DB-host RCE. Update to v0.63.0; least privilege.
2026.06.0253 views
News
Cloud Foundry UAA leaks its private key: CVE-2026-40965 (CVSS 10.0)
SecurityGlobal CompaniesInfrastructure
Cloud Foundry UAA exposes its EC private key via a public page (CVE-2026-40965, CVSS 10.0): token forgery risk. Only EC configs affected. Patch and rotate keys.
2026.06.0245 views
News
Oracle WebLogic vulnerabilities: exploited flaw and latest patch status
InfrastructureSecurityGlobal Companies
CISA added Oracle WebLogic CVE-2024-21182 to its KEV catalog as exploited in the wild. Data can be read without login; the fix shipped July 2024. What to check now.
2026.06.0278 views
News
Four WordPress plugins hit with critical takeover flaws: CVE-2026-48866 and 3 more
Global CompaniesSecurityDevelopment
Four popular WordPress plugins were hit with critical flaws (up to CVSS 9.8): file deletion in Gravity Forms (CVE-2026-48866) and unauthenticated site takeover in Contest Gallery, wpForo and AIWU. Who's affected and what to update now.
2026.06.0255 views
News
CATIA design-data server hijacked without login: CVE-2026-7858 (and DELMIA XSS CVE-2026-9024)
SecurityInfrastructureGlobal Companies
Dassault disclosed CVE-2026-7858 (CVSS 9.8): an unauthenticated takeover of the CATIA design-data server Teamwork Cloud, plus a DELMIA XSS flaw. Who's affected and what to do.
2026.06.0150 views
News
Major Vulnerabilities in Products Japanese Enterprises Use (2026)
SecurityJapanese CompaniesInfrastructure
In H1 2026, serious vulnerabilities hit products Japanese firms rely on, from Fujitsu and NEC to Microsoft and Oracle. A cross-vendor hub for in-house IT teams.
2026.06.0187 views
News
CVE-2026-48188: OTRS Helpdesk Auth Bypass, No Login Needed (Fix 2026.4.X)
PrivacySecurity
CVE-2026-48188 (CVSS 9.1) lets attackers break into the OTRS helpdesk with no login via unauthenticated SQL injection, but only when MySQL/MariaDB runs in NO_BACKSLASH_ESCAPES mode. Fixed in OTRS 2026.4.X; the end-of-life Community Edition 6.0.x is most at risk.
2026.06.0164 views