Tag

#vulnerability

96 stories taggedvulnerability · page 5 of 7.

Photoreal editorial image of a dimly lit server rack in a data centre, one blue status LED glowing, a faint reflection of scrolling log text on the glass door,
Vulnerabilities

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns

CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a data centre, one status light glowing red among rows of green, cool blue ambient lighting,
Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar

F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing a generic file-archive dialog with a compressed folder icon highlighted, warm desk lamp light, ou
Vulnerabilities

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code

Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

3 min read
Photoreal editorial shot of a server rack in a dim data centre, one blade glowing faintly red, cables neatly arranged, shallow depth of field, edge-to-edge comp
Vulnerabilities

An 11-byte message can knock OpenSSL servers offline, researchers warn

A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

3 min read
Full-frame photoreal editorial image of two identical brass keys resting on a dark steel surface under a single overhead light, each key tagged with a small bla
Identity & Access

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else

The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

3 min read
Full-frame photoreal editorial image of a dimly lit corporate server room with rows of blue-lit racks, a soft red warning glow pulsing from one rack indicating
Vulnerabilities

US government orders emergency patch for critical Oracle finance software flaw

CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

3 min read
A network operations room with servers labelled with F5, NGINX, and BIG-IP infrastructure, with patch alert notifications cascading across monitoring screens
Vulnerabilities

F5 Fixes Serious Security Flaws in NGINX and BIG-IP

Patches are now available for multiple vulnerabilities in two widely used networking products that could have let attackers take control of systems, crash services, or steal data.

3 min read
Full-frame photoreal editorial image of a close-up Windows laptop screen showing a generic blue security shield icon glowing, with faint reflection on a dark de
Vulnerabilities

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System

Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

3 min read
Photoreal news-editorial image, full-frame 16:9, edge to edge
Vulnerabilities

Zoom patches critical Windows flaw that could hand attackers your account

A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

3 min read
Full-frame edge-to-edge photoreal overhead shot of a sleek aluminum laptop on a dark desk, screen glowing with abstract hex dump and disassembly patterns in coo
AI Security

One Click Was All It Took to Hijack Anthropic's Claude AI

A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

3 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Vulnerabilities

Progress ShareFile zero-day forced emergency server shutdowns; patch is out

A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

3 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Vulnerabilities

Australia sounds the alarm: hackers are hijacking small business websites at scale

The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

3 min read
Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Vulnerabilities

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code

A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

3 min read
Photoreal editorial image, 16:9, full-frame edge to edge, of a dim server room with one rack unit powered off, its status lights dark while surrounding units gl
Vulnerabilities

Progress tells ShareFile customers to pull the plug amid 'credible' threat

The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

3 min read
Full-frame photoreal editorial shot of a modern laptop on a dark wooden desk, screen glowing with an abstract chat interface and a faint warning glyph reflected
AI Security

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer

A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

3 min read
© 2026 Threat Vectr