News
Azure Cosmos DB CVE-2026-66803: Fixed by Microsoft, No Action Needed
InfrastructureSecurity
Azure Cosmos DB had a CVSS 10.0 flaw (CVE-2026-66803) risking takeover of any database. Microsoft fixed it server-side; no user action, no known exploitation.
2026.07.3147 views
News
No victim reports after the CVE-2025-68686 deadline — and Fortinet still says 'not exploited'
SecurityInfrastructure
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
2026.07.3139 views
News
Cisco FMC Hardcoded Password CVE-2026-20316 Under Active Attack
Global CompaniesInfrastructureSecurity
Cisco FMC carries a password baked into the product. Unauthenticated login, active exploitation, CISA deadline August 1. And it was public four months earlier.
2026.07.3041 views
News
Chrome Fixes 41 Flaws, Six Critical and Four Android-Only
Global CompaniesAISecurity
Google shipped Chrome 151 on July 29, 2026 with 370 security fixes. No exploitation reported. Here is the breakdown and the truth about "382".
2026.07.30107 views
News
Apache Traffic Server: five more CVEs flip the ranking
SecurityInfrastructure
Apache disclosed 38 Traffic Server CVEs on July 29, 2026. Three hit 10.0 under CVSS 3.1 but 7.0-7.8 under 4.0, both official. And 9.1.15 does not exist.
2026.07.2937 views
News
No-login order tampering: nine WordPress flaws (CVE-2026-13692)
SecurityDevelopment
Nine WordPress flaws, July 29 2026: PayU CommercePro lets an unauthenticated attacker cut order totals to zero, three have no fix, and none carry an NVD score.
2026.07.2927 views
News
CVE-2026-65667 Gave Teams a 10.0. Here's What Actually Needs Patching
InfrastructureSecurity
Of the 51 entries Microsoft published on July 23, 2026, the 14 cloud entries including all six scored 10.0 are already fixed and need no customer action. The work sits with 25 Azure Linux and 12 Edge entries scored far lower.
2026.07.2936 views
News
libssh2: ten 2026 flaws, no release since 2024 (CVE-2026-66032)
SecurityDevelopment
Ten libssh2 flaws in 2026, and no upstream release since 2024. The client that connects out is what breaks. CVE-2026-66032 and three more remain unpatched.
2026.07.2931 views
News
ActiveMQ Shut Down Without Login: CVE-2026-59878, Fix in 5.19.9/6.2.8
DevelopmentSecurity
Apache ActiveMQ got two fixes on July 27, 2026: one lets anyone without a login stall the broker, the other lets a low-privilege user write past its limits.
2026.07.2933 views
News
Adobe Bridge and Photoshop: 9 Flaws Fixed, CVE-2026-48395 the Worst
SecurityGlobal Companies
Adobe disclosed 8 flaws in Bridge and 1 in the Photoshop installer. Opening an image file from a client can let attackers run code. Update to 16.0.6 or 15.1.7.
2026.07.2933 views
News
PostgreSQL Extension pglogical: CVE-2026-50736 Superuser Escalation
InfrastructureSecurityDevelopment
Four flaws hit pglogical, a PostgreSQL add-on. The side receiving replicated data runs at the top privilege, so whoever sends it can take over. Fixed in 2.4.8.
2026.07.2938 views
News
Dompdf: 6 Flaws Including CVE-2026-59941, PHP PDF Apps Need 3.1.6
SecurityDevelopment
Dompdf, the PHP library behind countless invoice and report PDFs, disclosed six flaws. A 58-byte image can exhaust server memory. The fix is 3.1.6.
2026.07.2922 views