Vulnerabilities — Page 32

Oracle Launches Monthly Patch Cycle With 35-Flaw Drop, Four CVEs Under Active PoC Threat
A CVSS 10 hole in REST Data Services leads the list. Four older bugs with public exploit code deserve faster attention than their scores suggest.

PoC Drops for 19-Year-Old Linux Kernel Privilege-Escalation Bug in CIFSwitch
A flaw that's been sitting in the kernel since the mid-2000s now has working exploit code. Low-privileged users can reach root.

Attackers Hammer WP Maps Pro Flaw to Mint Admin Accounts on WordPress Sites
A critical bug in the 15,000-install Envato plugin is being weaponized in the wild to seed rogue administrators.

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw
A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.

CIFSwitch: Linux Kernel Key-Handling Bug Hands Out Root Across Major Distros
A local privilege escalation in the kernel's CIFS authentication path lets an unprivileged user forge key descriptions and walk away with root.

One Bad Character in a Host Header Breaks Auth for Thousands of FastAPI Apps
A parsing gap in Starlette lets unauthenticated requests reach protected routes — and the blast radius runs deep into the AI inference stack.

Palo Alto GlobalProtect Auth Bypass Hits Live Exploitation
CVE-2026-0257 lets attackers stand up unauthorized VPN sessions against PAN-OS and Prisma Access. Patches are out. So are the exploits.

IBM and Red Hat Launch Project Lightwell to Tackle Open Source Vulnerabilities
With a $5 billion investment, Project Lightwell aims to expedite vulnerability remediation in open source software.

Notepad++ Flaws Allow Command Execution Via XML Files
Recent vulnerabilities in Notepad++ enable arbitrary code execution on Windows through XML manipulation.

Swiss Team Claims Quantum Chip Setup Generates Truly Perfect Random Numbers
ETH Zurich researchers say two superconducting qubits and 30 meters of microwave pipe can certifiably eliminate bias from cryptographic key generation — forever.

Microsoft and Researcher Nightmare Eclipse Trade Public Accusations Over Disclosure Gone Wrong
A researcher who published unpatched vulnerability details says Microsoft deleted his accounts and ruined his life. Microsoft says his drops put proof-of-concept code in criminals' hands. Neither is entirely wrong.

Critical Argument Injection Zero-Day in Gogs Puts Self-Hosted Git Servers at Risk
A CVSS 9.4 flaw lets authenticated attackers execute arbitrary code through maliciously named pull-request branches — no patch is available.

Critical Argument Injection Flaw in Gogs Remains Unpatched
Authenticated users can exploit a critical flaw in Gogs, posing security risks for internal Git deployments.

Authenticated RCE in Gogs Hits CVSS 9.4 — and There's No CVE Yet
A critical flaw in the self-hosted Git service lets any logged-in account execute arbitrary code on the server. The auth bar is low. The blast radius isn't.

Patched FortiClient EMS Flaw Still a Live Attack Vector for Credential Theft
Attackers are piggybacking on Fortinet's endpoint management tooling to push infostealers disguised as legitimate agent updates.