Vulnerabilities
120 articles RSS
Citrix Confirms Exploitation of Two Critical NetScaler RCE Flaws, CVE-2026-88771 and CVE-2026-88772, as CISA Adds Both to KEV Catalog
Citrix confirmed exploitation of two critical NetScaler ADC and Gateway flaws, both CVSS v4 9.5, and shipped fixes; CISA added both to its KEV catalog as of September 27, 2026.
Vercel Patches Critical Next.js ImageResponse RCE Traced to a Satori SVG-Escaping Flaw
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Critical Bifrost AI Gateway Flaw Let Attackers Run Commands Without Credentials
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Plugin4Shell Flaw Lets Repository Owners Swap Pinned Plugin Code in Claude Code, Codex, and Copilot
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
Rust Security Team Fixes Miri Bug That Let GitHub Actions Caches Leak Secrets to Pull Requests
The Rust Security Response Team disclosed and patched a Miri flaw that stored all environment variables in target/, letting cached CI output expose secrets to pull requests.
GitHub Security Lab Finds Same-Second Race Condition in JupyterLab CI Action That Enables Code Execution
A TOCTOU race in JupyterLab's update-snapshots-checkout GitHub Action let a same-second commit push bypass its authorization check and reach attacker-controlled code execution, GitHub Security Lab found.
GitSpawn Flaws Let Malicious .git Configs Run Attacker Code in Claude Code, Cursor, Codex, and Other AI Coding Agents
Manifold Security found eight flaws across seven AI coding agents that let a repository's git config silently execute code the moment it is opened.
Eight Stable Linux Kernels Patch a GSO Fragmentation Flaw Present Since Kernel 2.6.27
CVE-2026-80590, a bug letting unprivileged users trigger a kernel panic via mismarked IPv4/IPv6 fragments, is fixed across eight stable and longterm kernel releases.
Tenet Security's 'GhostJacking' Attack Tricked Claude Code Into Rewriting Cloudflare DNS Records 9 Times Out of 10
Researchers showed AI coding and security agents can be hijacked through poisoned Cloudflare, Datadog, and Sentry logs to rewrite DNS records and steal credentials.
Attackers Actively Exploit Critical Gitea RCE Flaw as CISA Adds It to KEV Catalog With August 28 Deadline
CISA added Gitea's CVE-2026-60004 remote code execution flaw to its KEV catalog after BleepingComputer reported attackers deploying cryptomining malware on unpatched servers.
PostgreSQL Ships Coordinated Release Fixing 28 CVEs Across Five Versions, Debuts 19 Beta 3
PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 landed August 13 alongside 19 Beta 3, patching 28 security flaws and over 110 bugs, with PostgreSQL 14 set to lose support in November.
Marimo Patches CVE-2026-75149, an 8.7-Severity Code-Injection Flaw Triggered by a Notebook's MCP Configuration
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.