#vulnerability
96 stories taggedvulnerability · page 5 of 7.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar
F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

An 11-byte message can knock OpenSSL servers offline, researchers warn
A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

n8n Login Bug Let a Valid Token From One Provider Log You In as Someone Else
The workflow automation platform matched users on a single ID field and ignored who issued the token. On Enterprise setups with more than one login provider, that was enough to walk in as another person.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Patches are now available for multiple vulnerabilities in two widely used networking products that could have let attackers take control of systems, crash services, or steal data.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

Zoom patches critical Windows flaw that could hand attackers your account
A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

One Click Was All It Took to Hijack Anthropic's Claude AI
A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

Progress ShareFile zero-day forced emergency server shutdowns; patch is out
A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code
A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

Progress tells ShareFile customers to pull the plug amid 'credible' threat
The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer
A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.