News
Cybozu Garoon CVE-2026-57279 affects only 6.17.0 and 6.17.1
SecurityJapanese Companies
A cross-site scripting flaw in Cybozu Garoon affects just two package-edition releases, 6.17.0 and 6.17.1. Fixed in 6.17.2. Here is how to tell in one check.
2026.08.0325 views
News
N-central: Patch to 2026.3.1.10 as Ransomware Follows CVE-2026-18577
InfrastructureSecurity
N-able N-central has a login bypass that hands over administrator accounts. The vendor rates it as actively attacked and has published indicators of compromise. Fixed in build 2026.3.1.7.
2026.08.0336 views
News
Sharp printer flaw CVE-2026-60011 affects 164 models, 78 get no fix
SecurityJapanese Companies
A flaw in 164 Sharp multifunction printer models lets stored scans be read without logging in. 78 models are past firmware support and get no fix at all.
2026.08.0332 views
News
Transformers path traversal writes files anywhere (CVE-2026-9856)
DevelopmentSecurityAI
Loading and saving a crafted Hugging Face model lets an attacker write files outside its folder. NVD's affected range is wrong — upgrade to 5.10.1 or later.
2026.08.0338 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
SecurityDevelopmentInfrastructure
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0327 views
News
Better Auth and 4 more: 11 CVEs, all already fixed (CVE-2025-71399)
SecurityDevelopment
Five projects got 11 CVE numbers on August 2, but none is a new flaw — every fix shipped between November 2025 and July 2026. Only FreeRDP needs action.
2026.08.0225 views
News
27 WordPress flaws at once, six with no patch: CVE-2026-16261
SecurityDevelopment
27 WordPress plugin and theme flaws landed on Aug 2, 2026. Six have no fix, and all six were pulled from the official directory, so no update notice appears.
2026.08.0249 views
News
Forged Apple login takes over WordPress admin: CVE-2026-8457 +2 flaws
DevelopmentSecurity
Three WordPress plugin flaws went public on Aug 1, 2026. A forged 'Sign in with Apple' token can make anyone an administrator; two others let visitors read server files.
2026.08.0229 views
News
FreeRDP 3.29.0 is not enough: update to 3.30.0 (CVE-2026-68579)
DevelopmentLinuxSecurity
FreeRDP, the open-source engine behind Remmina and most Linux remote-desktop apps, has fixed 22 security flaws, including two critical bugs that let a malicious or intercepting server bypass encryption and spy on or hijack your session. Update to version 3.29.0. CVE-2026-66402 and more.
2026.08.0133 views
News
AI Engine WordPress Plugin Vulnerabilities: 3.6.6 Is Not Enough, Update to 3.7.1
DevelopmentAISecurity
AI Engine WordPress plugin vulnerability roundup: CVE-2026-15988 and CVE-2026-65545. 3.6.6 is not enough, as 65545 affects 3.6.8 and below. Update to 3.7.1.
2026.08.0122 views
News
Critical ComfyUI Flaw CVE-2026-68771 Lets Anyone Take Over the Server: Update to v0.26.0
AISecurity
ComfyUI, the AI image-generation tool used worldwide, has a severity-9.8 flaw that lets anyone take over the server without logging in. If you expose it to the internet, a crafted file alone could run arbitrary programs on your machine. No attacks confirmed yet; here are the affected versions, how to update to v0.26.0, and how to review your exposure.
2026.08.0153 views
News
Critical pgAdmin Flaw CVE-2026-17566 Lets Users Take Over the Server: Update to v9.17
DevelopmentSecurity
pgAdmin, the standard tool for managing PostgreSQL databases, has seven vulnerabilities, led by a severity-9.9 flaw that lets a logged-in user take over the server with ordinary permissions. Exploitation could run arbitrary commands on the database server. No attacks confirmed yet; here is who is affected and how to update to v9.17.
2026.08.0131 views