News
Fluent Forms Pro shipped a backdoored update for five hours: CVE-2026-73532
DevelopmentSecurity
MonsterInsights Pro shipped malware after its update bucket was hijacked. The version it rolled back to was poisoned too. Three CVEs, 9.8+. Paid versions only.
2026.08.0756 views
News
Apache CXF's 12 flaws get scored — 'low' became 9.8, and Red Hat has not moved
DevelopmentSecurity
Apache CXF, the Java layer enterprises use for data exchange, has six new flaws. One lets a single message take over the server. Upgrade to 4.2.3/4.1.8/3.6.12.
2026.08.0640 views
News
TeamCity CVE-2026-63077 Is Being Exploited, Exploit Code Public
SecurityDevelopment
CISA gave US agencies three days to patch a TeamCity flaw that lets anyone take over the build server with no login. Self-hosted only; fixed since July 27.
2026.08.0632 views
News
24 WordPress plugin flaws: two-factor authentication itself can be bypassed (CVE-2026-15372)
SecurityDevelopment
Twenty-four WordPress plugin vulnerabilities were published on August 5, 2026, and four of them break two-factor authentication. WP 2FA never validated the second factor; miniOrange 2FA let an attacker re-point it. Four more expose password-protected content and three hand over the whole site. All 24 have fixed releases.
2026.08.0525 views
News
10 WordPress plugin flaws, 200,000-site PrettyLinks included — all already patched (CVE-2026-9273)
DevelopmentSecurity
Ten WordPress plugin vulnerabilities were published on August 5, 2026. The heaviest, in Kadence Memberships, lets an unauthenticated attacker hijack an administrator's password reset. All ten already have released fixes, the oldest from May 20 — only sites that stopped updating are at risk. PrettyLinks on 200,000 sites is included.
2026.08.0528 views
News
Five WordPress Plugin Flaws, All Ending in Account Takeover (CVE-2026-9273)
SecurityDevelopment
Five WordPress plugin vulnerabilities were published on August 5, 2026, and all five end in account takeover. Kadence Memberships lets an unauthenticated attacker hijack an administrator's password reset; Dokan lets anyone who can register as a vendor seize an administrator account. All five already have fixed releases, so updating ends it.
2026.08.0521 views
News
Jetty auth bypass CVE-2026-10050: non-ASCII passwords collapse to ?
DevelopmentSecurity
A Jetty flaw lets a login through without checking the password when it contains non-Latin characters. Only with Digest auth. Fixes for Jetty 9-11 are not free.
2026.08.0460 views
News
12 flaws in baserCMS, only one is traceable (CVE-2026-65875)
DevelopmentSecurity
baserCMS disclosed 12 flaws on July 30, 2026, three rated Critical. Eleven cannot be looked up by number, and Dependabot warns about none of them.
2026.08.0328 views
News
27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)
DevelopmentSecurity
27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.
2026.08.0326 views
News
27 WordPress plugin flaws: CVE-2026-15383 hits a Japan-made plugin
SecurityDevelopmentJapanese Companies
27 WordPress plugin flaws went public Aug 3, 2026. One hits a Japan-made plugin on 9,000 sites: any visitor can plant script that runs in the admin dashboard. It was quietly fixed July 31.
2026.08.0328 views
News
Transformers path traversal writes files anywhere (CVE-2026-9856)
SecurityAIDevelopment
Loading and saving a crafted Hugging Face model lets an attacker write files outside its folder. NVD's affected range is wrong — upgrade to 5.10.1 or later.
2026.08.0338 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
DevelopmentInfrastructureSecurity
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0327 views