News
FreeRDP 3.29.0 is not enough: update to 3.30.0 (CVE-2026-68579)
DevelopmentLinuxSecurity
FreeRDP, the open-source engine behind Remmina and most Linux remote-desktop apps, has fixed 22 security flaws, including two critical bugs that let a malicious or intercepting server bypass encryption and spy on or hijack your session. Update to version 3.29.0. CVE-2026-66402 and more.
2026.08.0114 views
News
AI Engine WordPress Plugin CVE-2026-15988: A Crafted Link Can Create a Secret Admin
DevelopmentAISecurity
A CSRF flaw (CVSS 8.8) in AI Engine, a WordPress AI plugin used on 100,000+ sites, lets an attacker create a hidden admin account if a logged-in admin opens a crafted link. Update to version 3.6.6 or later.
2026.08.0111 views
News
Critical ComfyUI Flaw CVE-2026-68771 Lets Anyone Take Over the Server: Update to v0.26.0
AISecurity
ComfyUI, the AI image-generation tool used worldwide, has a severity-9.8 flaw that lets anyone take over the server without logging in. If you expose it to the internet, a crafted file alone could run arbitrary programs on your machine. No attacks confirmed yet; here are the affected versions, how to update to v0.26.0, and how to review your exposure.
2026.08.0120 views
News
Critical pgAdmin Flaw CVE-2026-17566 Lets Users Take Over the Server: Update to v9.17
DevelopmentSecurity
pgAdmin, the standard tool for managing PostgreSQL databases, has seven vulnerabilities, led by a severity-9.9 flaw that lets a logged-in user take over the server with ordinary permissions. Exploitation could run arbitrary commands on the database server. No attacks confirmed yet; here is who is affected and how to update to v9.17.
2026.08.0114 views
News
Azure Cosmos DB CVE-2026-66803: Fixed by Microsoft, No Action Needed
InfrastructureSecurity
Azure Cosmos DB had a CVSS 10.0 flaw (CVE-2026-66803) risking takeover of any database. Microsoft fixed it server-side; no user action, no known exploitation.
2026.07.3130 views
News
Data-leak flaw in FortiGate (CVE-2025-68686) confirmed exploited: check for a prior breach
SecurityInfrastructure
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
2026.07.3123 views
News Updated 6 days ago
Cisco FMC Hardcoded Password CVE-2026-20316 Under Active Attack
Global CompaniesInfrastructureSecurity
Cisco FMC carries a password baked into the product. Unauthenticated login, active exploitation, CISA deadline August 1. And it was public four months earlier.
2026.07.3017 views
News Updated 3 days ago
Chrome Fixes 41 Flaws, Six Critical and Four Android-Only
Global CompaniesAISecurity
Google shipped Chrome 151 on July 29, 2026 with 370 security fixes. No exploitation reported. Here is the breakdown and the truth about "382".
2026.07.3052 views
News Updated 5 days ago
Apache Traffic Server: five more CVEs flip the ranking
SecurityInfrastructure
Apache disclosed 38 Traffic Server CVEs on July 29, 2026. Three hit 10.0 under CVSS 3.1 but 7.0-7.8 under 4.0, both official. And 9.1.15 does not exist.
2026.07.299 views
News Updated 7 days ago
No-login order tampering: nine WordPress flaws (CVE-2026-13692)
SecurityDevelopment
Nine WordPress flaws, July 29 2026: PayU CommercePro lets an unauthenticated attacker cut order totals to zero, three have no fix, and none carry an NVD score.
2026.07.2913 views
News Updated 4 days ago
Teams scored 10.0 in CVE-2026-65667: 17 cloud flaws, no action needed
InfrastructureSecurity
Of the 51 entries Microsoft published on July 23, 2026, the 14 cloud entries including all six scored 10.0 are already fixed and need no customer action. The work sits with 25 Azure Linux and 12 Edge entries scored far lower.
2026.07.2918 views
News
libssh2: ten 2026 flaws, no release since 2024 (CVE-2026-66032)
SecurityDevelopment
Ten libssh2 flaws in 2026, and no upstream release since 2024. The client that connects out is what breaks. CVE-2026-66032 and three more remain unpatched.
2026.07.299 views