Vulnerabilities — Page 33

Vulnerabilities

Microsoft and Researcher Nightmare Eclipse Trade Public Accusations Over Disclosure Gone Wrong

A researcher who published unpatched vulnerability details says Microsoft deleted his accounts and ruined his life. Microsoft says his drops put proof-of-concept code in criminals' hands. Neither is entirely wrong.

3 min read
Vulnerabilities

Critical Argument Injection Zero-Day in Gogs Puts Self-Hosted Git Servers at Risk

A CVSS 9.4 flaw lets authenticated attackers execute arbitrary code through maliciously named pull-request branches — no patch is available.

2 min read
Vulnerabilities

Critical Argument Injection Flaw in Gogs Remains Unpatched

Authenticated users can exploit a critical flaw in Gogs, posing security risks for internal Git deployments.

2 min read
Vulnerabilities

Authenticated RCE in Gogs Hits CVSS 9.4 — and There's No CVE Yet

A critical flaw in the self-hosted Git service lets any logged-in account execute arbitrary code on the server. The auth bar is low. The blast radius isn't.

2 min read
Vulnerabilities

Patched FortiClient EMS Flaw Still a Live Attack Vector for Credential Theft

Attackers are piggybacking on Fortinet's endpoint management tooling to push infostealers disguised as legitimate agent updates.

2 min read
Vulnerabilities

FortiClient EMS Flaw Sees Fresh Exploitation After April Hotfix

Attackers are still hitting a critical FortiClient EMS vulnerability that Fortinet patched — and flagged as actively exploited — months ago.

2 min read
Vulnerabilities

Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk

An account takeover vulnerability in the open-source call-for-papers platform Pretalx could allow an unauthenticated attacker to manipulate submission outcomes, researchers at Novee have found.

3 min read
Vulnerabilities

Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2

CVE-2026-27771 allowed anonymous pulls of private container images from all Gitea deployments prior to version 1.26.2, according to maintainers.

2 min read
Vulnerabilities

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited

The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

2 min read
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much — and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
Vulnerabilities

ChromaDB Flaw Exposes Servers to Remote Attacks

A vulnerability in ChromaDB allows attackers to execute code remotely, posing a risk to AI application servers.

2 min read
Vulnerabilities

Microsoft Rushes Fixes for Two Actively Exploited Defender Zero-Days as CISA Adds Both to KEV

A disgruntled researcher's GitHub exploits may be behind attacks on the Malware Protection Engine and Antimalware Platform — but Microsoft isn't saying so.

2 min read
Vulnerabilities

Cisco Secure Workload Flaw Demands Immediate Attention

Cisco Secure Workload vulnerability allows attackers admin-level access; patch now.

2 min read
Vulnerabilities

A Three-Year-Old Chromium Bug Can Turn Your Browser Into a Bot — And It's Still Not Fixed

An unpatched flaw in Chromium's Background Fetch API lets malicious websites keep service workers alive indefinitely, enabling crypto mining, DDoS participation, and persistent tracking across browser restarts.

3 min read
Vulnerabilities

Your CI Pipeline Is Already Too Late — CVE Lite CLI Disagrees With Your Entire Workflow

An OWASP-backed JavaScript dependency scanner built by Sonu Kapoor wants to catch vulnerable packages the moment a developer types the install command, not when the build breaks at 2 a.m.

3 min read
© 2026 Threat Vectr