News
Account-takeover flaw in Zoom's Windows apps, no login or interaction needed: CVE-2026-53412 — update to the latest version
Global CompaniesSecurity
A critical flaw, CVE-2026-53412 (CVSS 9.8), was found in the Windows version of the video-conferencing app Zoom. With no login and no user interaction, an account can be taken over over the network. The affected products are the Windows desktop, VDI, and developer SDK versions; Mac and mobile are not affected. Fixed versions are out, so updating to the latest is recommended.
2026.07.1718 views
News
Document-to-AI tool Docling hit by a string of flaws: crafted documents or URLs can leak internal information — CVE-2026-44023 and 7 more, update now
AISecurity
Docling, a popular tool for feeding PDFs and Word files into AI, has eight flaws led by CVE-2026-44023 (severity 8.6) that can be used to steal internal files and information via crafted documents or URLs. They include SSRF and XXE and affect setups that process untrusted data. Updating docling-core to 2.74.1 and the main docling to 2.94.0 or later fixes them. No real-world attacks confirmed.
2026.07.1732 views
News
WireGuard Easy (wg-easy) flaw lets attackers steal VPN connection details — dangerous if the admin panel is exposed: CVE-2026-63089, no stable fix released yet
SecurityInfrastructure
A critical flaw, CVE-2026-63089 (CVSS 9.3), was found in WireGuard Easy (wg-easy), a popular tool for standing up a VPN with no fiddly setup. The token on its single-use share link has only 1,000 possibilities and no attempt limit, so if the admin panel is exposed to the internet, attackers can steal VPN connection settings without logging in. No stable fix has been released yet; for now you must keep the admin panel off the internet.
2026.07.1744 views
News
Grafana OnCall (open-source) can be fully taken over without login — and no patch is coming: CVE-2026-63087, stop using it and migrate
InfrastructureSecurity
A critical flaw, CVE-2026-63087 (CVSS 9.8), lets anyone take over Grafana OnCall (the open-source on-call/alerting tool) completely without logging in. The open-source edition is already end-of-life, so no patch is coming. All versions are affected; block the management port now and migrate to the supported successor.
2026.07.1752 views
News
Critical flaw in a tool bundled with Ubuntu (CVE-2026-11386): a spoofed server could sneak in malicious software — update now
SecurityLinux
A critical flaw, CVE-2026-11386 (CVSS 9.0), was found in ubuntu-pro-client, a tool bundled with Ubuntu and used on servers worldwide. Loose validation of the contract server's response lets a spoofed server rewrite where software is fetched from and plant malicious packages. All supported LTS releases are affected; a normal security update applies the fix.
2026.07.1621 views
News
Critical flaw in Spring Authorization Server (CVE-2026-22752): a crafted client registration can lead to impersonation and data theft — update to 7.0.5 / 1.5.7
SecurityDevelopment
A critical flaw, CVE-2026-22752 (CVSS 9.6), has been disclosed in Spring Authorization Server, the Java foundation used for login integration in enterprise systems. When Dynamic Client Registration is enabled, crafted data can lead to impersonation, privilege escalation, and internal probing. The fix is to update to 7.0.5 or 1.5.7, or to disable dynamic registration.
2026.07.1633 views
News
Three popular WordPress plugins hit by admin-takeover flaws, including a translation tool on 1M+ sites (CVE-2026-15005 and more) — update now (July 16, 2026)
SecurityDevelopment
On July 16, 2026, three popular WordPress plugins were disclosed to carry serious takeover flaws: the translation tool Loco Translate (1M+ installs), the phone-number login plugin Digits, and the funnel builder WPFunnels. All three can let an attacker impersonate an administrator, rated 8.8 out of 10. Updating each plugin to its latest version resolves the risk.
2026.07.1628 views
News
Credit cards went down across Japan on July 16: convenience stores and Suica top-ups hit — the cause was an international card network outage
MobileJapanese CompaniesInfrastructure
On the morning of July 16, 2026, credit card payments briefly failed at convenience stores, drugstores, and station ticket machines across Japan, and Mobile Suica and PASMO top-ups were hit too. The cause was a failure in the international payment network linking card companies; it recovered by midday. Cash and already-charged balances still worked. Here is what happened, in order.
2026.07.16143 views
News
Critical flaw in the WordPress plugin miniOrange SAML SSO (CVE-2026-15013): admin takeover with no password — update to 5.4.4
DevelopmentSecurity
A critical flaw, CVE-2026-15013, was found in the WordPress SSO plugin 'SAML Single Sign On – SSO Login' (miniOrange). An attacker with no password could bypass signature verification, impersonate an administrator, and take over the site. Severity is CVSS 9.8, with 10,000+ installs. We cover updating to 5.4.4 and how to check for compromise.
2026.07.1622 views
News
Signature forgery flaws in node-forge, a JS crypto library with 34M weekly downloads (CVE-2026-33894, CVE-2026-33895): update to 1.4.0
DevelopmentSecurity
node-forge, a JavaScript crypto library with about 34.4M weekly downloads, has two signature-forgery flaws (CVE-2026-33894, CVE-2026-33895). An attacker's forged signature could be accepted as genuine, bypassing authentication and code signing. Both are High (CVSS 7.5). We cover how to check exposure and update to 1.4.0.
2026.07.1631 views
News
Two flaws in Tera Term (CVE-2026-58317 and CVE-2026-60060): a malicious SSH server could leak your PC's memory — update to 5.6.2
SecurityDevelopment
Two flaws (CVE-2026-58317, CVE-2026-60060) were found in Tera Term, a popular Japanese tool for connecting to servers. Connecting to a malicious server could leak your PC's memory or crash the app. Severity is medium with no observed abuse; we explain who is affected and how to update to 5.6.2.
2026.07.1643 views
News
Tomcat CVE-2026-34486 Is Under Attack: Only Three Builds Affected, Deadline August 7
DevelopmentSecurity
Apache Tomcat flaws CVE-2026-59083 and 59084 show up as a '9.1 (Critical)' in scanners, but Apache itself rates both 'Low' — no real exploitation, not in KEV. We explain calmly why the numbers disagree, whether your setup is affected, and why a routine update is enough.
2026.07.16107 views