News
Axis2 CVE-2026-66713 Rates 9.8 But Only Hits a Default-Off Feature
SecurityInfrastructureDevelopment
Apache Axis2 flaw CVE-2026-66713 shows 9.8 on NVD, but it only applies if you enabled a feature that ships disabled. How to check, and which release fixes it.
2026.07.2951 views
News
Terraform MCP Server: Others Can Act With Your Token (CVE-2026-16498)
AIInfrastructureSecurity
HashiCorp's official Terraform MCP server had three flaws letting one user act with another's credentials. CVE-2026-16498 scores 10.0. Fixed in 1.1.0.
2026.07.2945 views
News
WebSphere: 14 Flaws, Server Takeover Without a Login (CVE-2026-14512)
SecurityInfrastructure
IBM disclosed 14 WebSphere Application Server flaws on July 28, 2026. The worst lets attackers take over the server with no login. Fix Packs slip to September.
2026.07.2942 views
News
ManageEngine ADAudit Plus Unauthenticated RCE: CVE-2026-6516, CVSS 10
InfrastructureSecurity
ManageEngine ADAudit Plus has a CVSS 10.0 flaw: no login needed to run code on the server watching every AD account change. Builds below 8606 affected.
2026.07.2964 views
News
Tegalog flaw lets anyone log in as admin (CVE-2026-64940)
SecurityJapanese Companies
Tegalog, used on many Japanese personal sites, lets a stranger into the admin screen without logging in. Only version 4.9.0 is safe.
2026.07.2919 views
News
Three Galaxy flaws exploitable with no user action, fixed in the July update (CVE-2026-21047)
SecurityMobile
Samsung's July 2026 Galaxy update fixes three flaws exploitable with no user action. Two sit in the same image codec that spyware exploited last year.
2026.07.2822 views
News
RabbitMQ can be taken down with no login, and no fixed release yet (CVE-2026-59248)
SecurityInfrastructure
An unauthenticated attacker can exhaust memory and take RabbitMQ down via its management ports. Every released version including 4.3.4 is affected, and no fixed RabbitMQ release exists yet.
2026.07.2829 views
News
Three flaws across seven ELECOM Wi-Fi routers and access points (CVE-2026-59764)
SecurityJapanese Companies
Three flaws in seven ELECOM Wi-Fi routers and access points, July 28 2026. Fixed firmware shipped in May and June; the consumer models auto-update by default.
2026.07.2829 views
News
Bouncy Castle 1.85 fixes 32 CVEs, and no scanner will flag them
SecurityDevelopment
A timing flaw in Bouncy Castle's post-quantum ML-KEM code can leak a private key. It was already fixed in 1.78 (April 2024); only versions 1.73 to 1.77 are exposed.
2026.07.2865 views
News
3DEXPERIENCE hit by a perfect 10.0 flaw: CVE-2026-11756 targets the designer's PC
Global CompaniesSecurity
A perfect 10.0 flaw in 3DEXPERIENCE: CVE-2026-11756 needs no login, hits the Station Launcher App on engineers' PCs, and the fixed build is not public.
2026.07.2837 views
News
Eighteen WordPress plugin flaws, two with no fix at all (CVE-2026-15014)
DevelopmentSecurity
Eighteen WordPress plugin flaws, July 28 2026 — eleven need no login and two have no fix at all. Bookly's published affected range is wrong: 27.7 is still exploitable.
2026.07.2845 views
News
vBulletin Forum Software Hit by Critical Flaw CVE-2026-61511: Unauthenticated Server Takeover
SecurityDevelopment
vBulletin, the forum software used by community sites worldwide, has a flaw (CVE-2026-61511, severity 9.8) that lets anyone take over the server without logging in. A working exploit was published on July 27, 2026, though no in-the-wild attacks have been confirmed. Versions up to 5.7.5 and 6.2.1 are affected; the fix is to update to 6.2.2 immediately.
2026.07.28309 views