Tag

#vulnerability

80 stories taggedvulnerability.

Full-frame close-up photograph of an industrial smart plug device mounted on a metal DIN rail inside a factory electrical cabinet, cool blue LED status light gl
Vulnerabilities

Siemens Patches High-Severity Flaw in Parasolid 3D Modelling Engine

A memory-handling bug in Siemens Parasolid, tracked as CVE-2026-64629, lets a booby-trapped design file crash the host application or run attacker code. Siemens has shipped fixed builds.

3 min read
Photoreal editorial shot of a modern office desk with an open laptop showing a generic email client interface, soft daylight from a window, muted blue and grey
Vulnerabilities

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company

A security research team chained together four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

4 min read
A computer screen displaying Ubuntu Desktop with a lock symbol, symbolizing security vulnerability
Vulnerabilities

Hackers Exploit Patched VMware vCenter Flaw as Regulators Watch Disclosure Clocks

A directory-traversal bug rated 9.8 out of 10 is under active attack, and SEC and EU disclosure duties now sit squarely on affected firms.

4 min read
Full-frame photoreal editorial image of a dimly lit enterprise data centre aisle, rows of server racks with soft blue and amber status lights, one rack door sli
Vulnerabilities

SAP patches perfect-10 flaw in Commerce Cloud that let anyone run code

CVE-2026-58231 carries the highest possible severity score. Unauthenticated attackers could execute arbitrary code on affected Commerce Cloud installs.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

A Single Click Could Have Handed Hackers Your Company's Confluence and Jira Files

Researchers found a flaw in Atlassian's Rovo AI assistant that let an attacker steal data from widely used workplace tools with almost no effort from the victim.

3 min read
Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Vulnerabilities

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It

A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

3 min read
Full-frame 16:9 photoreal editorial shot of a darkened desk with a gaming laptop open, screen glowing with a generic browser window and a translucent overlay su
Vulnerabilities

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical

The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

3 min read
Full-frame edge-to-edge photoreal overhead shot of a generic unbranded smartphone on a dark slate surface, screen glowing with abstract green security shield ic
Vulnerabilities

Researchers Cracked Samsung Phones Wide Open by Turning Bixby Against Its Own Device

A five-step exploit chain using Bixby, Samsung Members, and Samsung Account could hand a stranger complete control of your Galaxy phone. Patches are out, but older devices may still be exposed.

4 min read
Close-up overhead shot of a plain laptop keyboard in a dimly lit office, the screen glowing pale blue, an inbox interface faintly reflected on the desk surface,
AI Security

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host

Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

4 min read
Photoreal editorial image, 16:9, full-frame edge to edge, of a dim server room with one rack unit powered off, its status lights dark while surrounding units gl
Vulnerabilities

Thermo Fisher patches DNA analysis flaw that could let evidence files be quietly altered

A vulnerability in Applied Biosystems human identification software could allow near-invisible edits to forensic DNA files before analysts ever see them.

4 min read
An AI scanning software code for vulnerabilities
AI Security

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine

Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

4 min read
Full-frame edge-to-edge photoreal close-up of intertwined fiber-optic cables glowing with cool blue light, threaded through a darkened server rack, one strand v
Vulnerabilities

N-able confirms hackers seized N-central servers through a login-bypass flaw

The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

3 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely

A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

4 min read
A glowing server rack in a dark data center, one rack unit pulsing with deep red light indicating a fault or intrusion, surrounded by cold blue ambient light fr
Vulnerabilities

Schneider Electric patches a nasty file-parsing bug in its industrial control software

A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

3 min read
Photoreal editorial shot of a dimly lit server rack with a single glowing amber warning light, faint reflections of code on the metal, shallow depth of field, c
Vulnerabilities

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload

CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.

3 min read
© 2026 Threat Vectr