News
Four critical flaws in Tenable Security Center: CVE-2026-64878 et al. — post-login takeover, update to 6.8.0
InfrastructureSecurity
Tenable Security Center (formerly Tenable.sc), a vulnerability-management product, has five serious flaws. CVE-2026-64878 and CVE-2026-64879 (9.9) let a logged-in user run commands on the server (takeover); CVE-2026-64877 (8.4) lets a low-privileged user pull sensitive data. Affected: Linux builds before 6.8.0 — update to 6.8.0 or apply patch SC202607.1.
2026.07.2227 views
News
SolarWinds Serv-U: 15 flaws fixed in 2026.3 (CVE-2026-28302 et al.)
SecurityInfrastructure
SolarWinds Serv-U, used for enterprise file transfer, has 14 flaws rated 9.1 disclosed at once (CVE-2026-28302 et al.). An admin-privileged user can read/write files beyond limits and reach privileged code execution (server takeover), with larger impact on Linux/Unix. Affected: 15.5.4 HF1 and earlier; update to the latest hotfix.
2026.07.2232 views
News
Home Assistant: 2026.6.0 is not enough, CVE-2026-64824 needs 2026.7.0
InfrastructureSecurity
Home Assistant, the popular free smart-home platform, has a flaw rated 9.3. CVE-2026-64825 lets a crafted backup — loaded during setup or restore — write an arbitrary file on the device, leading to takeover on root-running installs. No login needed. All versions before 2026.6.0 are affected; here's how to update.
2026.07.2233 views
News
Ninja Forms: seven flaws, one lets buyers pay zero. Update to 3.15.0
DevelopmentSecurity
Ninja Forms, a WordPress form-builder used on 600,000+ sites, has two flaws rated 9.3. CVE-2026-65048 can take over an administrator from a form submission with no login; CVE-2026-65049 can bulk-delete all form data on multisite. Fix 3.14.9 (latest 3.14.10) is out — here's how to update and confirm you're safe.
2026.07.2230 views
News
Pre-Login Takeover Flaw in Linux Remote Desktop 'xrdp': 10 Flaws Fixed at Once (CVE-2026-41252), Update to 0.10.6.1
LinuxSecurity
xrdp, the popular software that accepts Windows Remote Desktop connections to Linux, has a worst-tier flaw exploitable without a password. A malicious relay destination alone can lead to remote takeover, and version 0.10.6.1 fixes 10 flaws at once. Here is who is affected and how to update on each Linux.
2026.07.2138 views
News
Chiikawa Movie Tickets: Cinema Booking Sites Crash at Once in the Midnight Seat Rush
InfrastructureJapanese Companies
At midnight on July 21, as advance reserved-seat sales for the Chiikawa movie opened, cinema booking sites including TOHO Cinemas, AEON Cinema and United Cinemas went down one after another under a traffic surge. Here is what happened, why hit-title launches crash these sites, and what to do if you can't get through.
2026.07.2133 views
News
Sagawa Express leaks ~70,000 users' data: delivery emails showed other people's names, caused by a config error
Japanese CompaniesSecurityPrivacy
Japanese delivery giant Sagawa Express says up to about 70,000 users' personal data may have leaked through its "Smart Club" service. Delivery notification emails showed another person's name, email address and parcel tracking number. The cause was not a cyberattack but a configuration mistake made during recovery work. Here is what leaked, what did not, and how to avoid the Sagawa-impersonating scam emails that follow.
2026.07.2042 views
News
Unauthenticated takeover flaw in VMware Avi Load Balancer: CVE-2026-47865 — patch to 32.1.2 now
SecurityInfrastructure
VMware's Avi Load Balancer, which many companies place in front of their servers, has a flaw (CVE-2026-47865, severity 9.8) that lets attackers take over its management console with no login. Seven flaws in total were disclosed, with fixes 32.1.2, 31.2.2-2p3 and 30.2.7 now available. There is no workaround. Here's how to check whether your version is affected and update.
2026.07.1824 views
News
Perfect-10 unauthenticated takeover in PrestaShop's search module: CVE-2026-54159 — update ps_facetedsearch to 4.0.4
SecurityDevelopment
PrestaShop, the popular free software for building online stores, has a maximum-severity (10.0) flaw in its standard filtered-search feature. Tracked as CVE-2026-54159, a single crafted URL can take over the shop and server with no login. The affected module is Faceted Search 3.0.0-4.0.3; update to 4.0.4.
2026.07.1837 views
News
WordPress core flaws CVE-2026-60137 / CVE-2026-63030: update now
SecurityDevelopment
WordPress, used by about 40% of all websites, has two database-tampering flaws (SQL injection) in its core. Tracked as CVE-2026-60137 and CVE-2026-63030, when chained they can let attackers take over a site with no login. Fixes 6.8.6, 6.9.5, and 7.0.2 shipped and auto-updates were force-pushed. Here's how to confirm your site is already fixed.
2026.07.18156 views
News
Just opening a repo in Cursor can hijack a Windows PC: CVE-2026-63093, and there's still no official fix
DevelopmentAISecurity
A flaw in the Windows version of Cursor, the AI code editor used by over 7 million developers, can let attackers run code on your PC just by getting you to open a booby-trapped repository. Tracked as CVE-2026-63093 (severity 8.8), it has no published fixed version — Cursor calls it out of scope, so users must protect themselves for now.
2026.07.1831 views
News
Takeover-enabling flaws in the popular self-hosted AI agent OpenClaw, plus no-login impersonation in its checker: CVE-2026-62241 and 9 more — update now
AISecurity
A wave of vulnerabilities has hit OpenClaw, the popular self-hosted AI agent used worldwide, letting people do things they shouldn't. Its companion security-checking tool has a critical (9.1) flaw allowing user impersonation with no login. Fixed versions are out: update OpenClaw to 2026.6.9+ and the checker to 0.7.5+. Here are the affected products and how to fix them.
2026.07.1747 views