Vulnerabilities — Page 22

Unpatched Flaw in Alibaba's XQUIC Lets Anyone Crash HTTP/3 Servers With 260 Bytes
A researcher at FoxIO disclosed the bug on 8 July. There is no fix, no login required, and no malformed packets involved.

'Ill Bloom' Wallet Flaw Drains $3.1 Million as Weak Recovery Phrases Give Thieves the Keys
Security firm Coinspect says attackers are already sweeping wallets whose recovery words were generated with predictable randomness.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure
The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

Google Patches 27 Chrome Flaws, Two Rated Critical
Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat
The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

A Secret Backdoor in Tenda Home Routers Lets Strangers Take Control, and There Is No Fix
A hidden login trick buried in Tenda networking gear gives anyone who knows the magic password full administrative control. The maker has not responded, and no patch exists.

Ubiquiti Rushes Fixes for a 10-out-of-10 Flaw Across UniFi Gear
The networking vendor patched serious holes in UniFi Connect, Talk, Access, Protect and the underlying UniFi OS. One bug scores a perfect 10 on the severity scale.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS
The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD
Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines
A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.