#vulnerability
80 stories taggedvulnerability.

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine
A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company
A security research team chained together four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks
A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

SAP patches perfect-10 flaw in Commerce Cloud that let anyone run code
CVE-2026-58231 carries the highest possible severity score. Unauthenticated attackers could execute arbitrary code on affected Commerce Cloud installs.

A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files
Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device
A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

Thermo Fisher patches DNA analysis flaw that could let evidence files be quietly altered
A vulnerability in Applied Biosystems human identification software could allow near-invisible edits to forensic DNA files before analysts ever see them.

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

Schneider Electric patches a nasty file-parsing bug in its industrial control software
A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload
CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.