Vulnerabilities — Page 14

Full-frame photoreal editorial shot of a laptop screen showing a generic file-archive dialog with a compressed folder icon highlighted, warm desk lamp light, ou
Vulnerabilities

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In

CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.

3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Arista rushes fix for VeloCloud flaw already being used in attacks

A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

4 min read
A close-up, macro, photoreal, news-editorial shot of a tangled cluster of worn ethernet and USB cables plugged into a dusty server strip, bathed in the cool blu
Vulnerabilities

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code

Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

4 min read
A computer screen displaying Ubuntu Desktop with a lock symbol, symbolizing security vulnerability
Vulnerabilities

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server

A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

3 min read
Close-up overhead view of a modern Android smartphone lying face-up on a dark matte desk, its screen glowing with a soft blue-white light, surrounded by faint a
Vulnerabilities

What Is Really Inside Your Work Apps? Lookout's New Tool Aims to Tell You

A new scanning service from mobile security firm Lookout builds detailed ingredient lists for enterprise apps, exposing hidden vulnerable components before criminals can exploit them.

3 min read
A digital shield protecting a SharePoint server
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

4 min read
Close-up top-down view of a sleek aluminum laptop keyboard and trackpad on a matte desk surface, soft cool studio lighting casting subtle shadows, a faint abstr
Vulnerabilities

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers

A researcher published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

3 min read
A digital illustration of a hacker exploiting a Windows driver without hardware, with a focus on code interaction diagrams
Vulnerabilities

Rockwell Automation Fixes Four Code-Execution Bugs in Arena Simulation Software

A crafty booby-trapped file is all it takes to trigger the flaws. Hospitals, defence contractors and supply-chain firms all run the software.

3 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial image of an open laptop on a dark desk showing a blue Windows-style recovery screen glow reflecting off th
Vulnerabilities

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity

A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Vatican Prayer App Left 700,000 Users' Names and Emails Exposed for Anyone to Grab

A basic security blunder on the Catholic Church's official Click to Pray app meant that anyone with a browser could pull the personal details of every registered user, no hacking skills required.

4 min read
Full-frame close-up of a modern laptop screen glowing blue in a dim office, showing an abstract Windows security shield icon partly fractured, dust motes catchi
Vulnerabilities

Certighost: New Exploit Turns Ordinary Windows Users Into Domain Controllers

A public proof-of-concept lets any low-privileged Active Directory account impersonate a domain controller and walk off with the crown jewel of Windows authentication.

3 min read
A close-up of a laptop screen glowing softly in a dim home office, showing an abstract blue Windows-style update progress bar and shield icon, no readable text
Vulnerabilities

Three Security Stories You May Have Missed: Industrial Switches, Russian Email Spying, and a Rail Ransomware Shakedown

A digest of under-reported threats: flaws in Siemens industrial network hardware, a Russian hacking campaign targeting Zimbra webmail servers, and a ransomware attack against Swiss train maker Stadler Rail.

3 min read
Close-up overhead view of a modern Android smartphone lying face-up on a dark matte desk, its screen glowing with a soft blue-white light, surrounded by faint a
Vulnerabilities

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers

Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

3 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Vulnerabilities

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days

Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

3 min read
Photoreal news-editorial shot of a stack of rack-mounted network appliances in a dim server room, faint amber status LEDs reflecting off polished floor tiles, s
Vulnerabilities

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software

Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

3 min read
© 2026 Threat Vectr