-
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API and was discovered by researcher E…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adobe has released a critical security update for Adobe Campaign Classic to address multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code and access sensitive data through unauthorized file system reads. This advis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability. This flaw could allow attackers to gain unauthorized access to affected systems by exploiting weaknesses in SAML-based single sign-o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-ser…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the se…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers at Wiz found CosmosEscape in Azure’s Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of act…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite feature could be exploited to steal Supervisor tokens and ultimately execute commands as root …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes for seven critical-severity flaws that affect core components of the browser. The new versions are …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


