News Updated 5 days ago
Ten Flaws in Cisco IOS XE, Found by Cisco Itself — No Workarounds
SecurityInfrastructure
Cisco disclosed ten IOS XE vulnerabilities at once, the worst rated 9.8, none with a workaround. They did not surface through attacks — Cisco found them in its own internal review.
2026.08.0613 views
News Updated 6 days ago
Two Flaws in Japan's NetKids iMark Network Monitor, and No Fixed Version Exists
Japanese CompaniesSecurityInfrastructure
Two vulnerabilities were disclosed in NetKids iMark, a Japanese-made network monitoring tool, on August 5, 2026. Anyone who can log in to the machine can seize SYSTEM privileges. Every build up to and including the current V5.2.5.0 is affected and no fix has shipped. Neither works over the internet, but a monitoring server holds the map of your network. Here are the two workarounds.
2026.08.058 views
News Updated 5 days ago
Both N-central Auth Bypass Flaws Now Exploited; Patch to 2026.3.1.7
InfrastructureSecurity
N-able N-central has a login bypass that hands over administrator accounts. The vendor rates it as actively attacked and has published indicators of compromise. Fixed in build 2026.3.1.7.
2026.08.0317 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
DevelopmentInfrastructureSecurity
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0312 views
News
Azure Cosmos DB CVE-2026-66803: Fixed by Microsoft, No Action Needed
InfrastructureSecurity
Azure Cosmos DB had a CVSS 10.0 flaw (CVE-2026-66803) risking takeover of any database. Microsoft fixed it server-side; no user action, no known exploitation.
2026.07.3131 views
News
Data-leak flaw in FortiGate (CVE-2025-68686) confirmed exploited: check for a prior breach
SecurityInfrastructure
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
2026.07.3123 views
News Updated 6 days ago
Cisco FMC Hardcoded Password CVE-2026-20316 Under Active Attack
SecurityGlobal CompaniesInfrastructure
Cisco FMC carries a password baked into the product. Unauthenticated login, active exploitation, CISA deadline August 1. And it was public four months earlier.
2026.07.3017 views
News Updated 5 days ago
Apache Traffic Server: five more CVEs flip the ranking
InfrastructureSecurity
Apache disclosed 38 Traffic Server CVEs on July 29, 2026. Three hit 10.0 under CVSS 3.1 but 7.0-7.8 under 4.0, both official. And 9.1.15 does not exist.
2026.07.299 views
News Updated 4 days ago
Teams scored 10.0 in CVE-2026-65667: 17 cloud flaws, no action needed
SecurityInfrastructure
Of the 51 entries Microsoft published on July 23, 2026, the 14 cloud entries including all six scored 10.0 are already fixed and need no customer action. The work sits with 25 Azure Linux and 12 Edge entries scored far lower.
2026.07.2918 views
News
PostgreSQL Extension pglogical: CVE-2026-50736 Superuser Escalation
DevelopmentInfrastructureSecurity
Four flaws hit pglogical, a PostgreSQL add-on. The side receiving replicated data runs at the top privilege, so whoever sends it can take over. Fixed in 2.4.8.
2026.07.2910 views
News
Axis2 CVE-2026-66713 Rates 9.8 But Only Hits a Default-Off Feature
DevelopmentInfrastructureSecurity
Apache Axis2 flaw CVE-2026-66713 shows 9.8 on NVD, but it only applies if you enabled a feature that ships disabled. How to check, and which release fixes it.
2026.07.2917 views
News
Terraform MCP Server: Others Can Act With Your Token (CVE-2026-16498)
SecurityAIInfrastructure
HashiCorp's official Terraform MCP server had three flaws letting one user act with another's credentials. CVE-2026-16498 scores 10.0. Fixed in 1.1.0.
2026.07.2917 views