Vulnerabilities — Page 14

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.

Arista rushes fix for VeloCloud flaw already being used in attacks
A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You
A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet
CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
A researcher published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

Rockwell Automation Fixes Four Code-Execution Bugs in Arena Simulation Software
A crafty booby-trapped file is all it takes to trigger the flaws. Hospitals, defence contractors and supply-chain firms all run the software.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

Vatican Prayer App Left 700,000 Users' Names and Emails Exposed for Anyone to Grab
A basic security blunder on the Catholic Church's official Click to Pray app meant that anyone with a browser could pull the personal details of every registered user, no hacking skills required.

Certighost: New Exploit Turns Ordinary Windows Users Into Domain Controllers
A public proof-of-concept lets any low-privileged Active Directory account impersonate a domain controller and walk off with the crown jewel of Windows authentication.

Three Security Stories You May Have Missed: Industrial Switches, Russian Email Spying, and a Rail Ransomware Shakedown
A digest of under-reported threats: flaws in Siemens industrial network hardware, a Russian hacking campaign targeting Zimbra webmail servers, and a ransomware attack against Swiss train maker Stadler Rail.

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers
Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.