#vulnerability
81 stories taggedvulnerability · page 2 of 6.

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload
CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

OpenAI Patches ChatGPT Flaw That Let Attackers Plant an Invisible AI Agent Inside a Company
A vulnerability called AgentForger meant a criminal could quietly create a rogue AI assistant inside a victim organisation, give it instructions, and control it from the outside.

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited
A critical authentication bypass in Check Point's management console let attackers waltz past the login screen. The vendor confirms real-world attacks are already happening.

Critical Ubuntu Flaw Allows Local Users Full Control
Security researchers reveal a serious vulnerability in Ubuntu's snap-confine that could let users gain root access.

Adobe Acrobat Extension Flaw Exposed WhatsApp Data
A vulnerability in the Adobe Acrobat Chrome extension could have silently hijacked WhatsApp web data of millions.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws
Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar
F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

An 11-byte message can knock OpenSSL servers offline, researchers warn
A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

Zoom patches a flaw that could hand strangers full control of your account
A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.