Vulnerabilities
89 articles RSS
Coinspect Discloses 'Ill Bloom' Flaw That Has Drained at Least $5 Million From Weak-Randomness Crypto Wallets
Coinspect says a weak-randomness flaw in recovery-phrase generation, dubbed Ill Bloom, has let attackers drain at least $5 million from crypto wallets since May 27.
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Flaws Across Its IDE Ecosystem
JetBrains patched three critical Hub and YouTrack flaws enabling account takeover and authentication bypass, alongside code-execution fixes across IntelliJ, GoLand, and TeamCity.
Adobe Patches Seven Maximum-Severity ColdFusion and Campaign Classic Flaws, Each Rated CVSS 10.0 for Code Execution
Adobe's July 1 updates fix seven CVSS 10.0 flaws—six in ColdFusion, one in on-premises Campaign Classic—that can lead to arbitrary code execution.
CISA Sets a July 2 Deadline as SimpleHelp Auth-Bypass Flaw CVE-2026-48558, Rated CVSS 10, Is Exploited to Deploy Djinn Stealer
A perfect-score authentication bypass in SimpleHelp's OIDC login is being exploited in the wild to deploy TaskWeaver and Djinn Stealer, prompting CISA to give federal agencies until July 2 to patch.
CISA Adds Actively Exploited SharePoint RCE CVE-2026-45659 to KEV, Giving Federal Agencies Three Days to Patch
A deserialization flaw in on-premises SharePoint, patched in May, is now confirmed under active exploitation, with a July 4 federal deadline.
DifyTap: Four Authorization Flaws Let Attackers Silently Wiretap AI Chats Across Tenants on a Platform Powering Over 1 Million Apps
Zafran Security disclosed four authorization flaws in the open-source LLMOps platform Dify, including two critical bugs that let an attacker redirect another tenant's AI conversations to an attacker-controlled endpoint.
CISA Adds Max-Severity Joomla Content Editor Flaw CVE-2026-48907 to KEV as Attackers Drop Web Shells via Rogue Editor Profiles
An unauthenticated RCE in the JCE extension, scored CVSS 4.0 10.0, is being exploited to plant web shells. CISA set a June 19 federal deadline.
Node.js Patches 12 CVEs in June Security Release, Two Rated High, as End-of-Life Node 20 Is Left Without a Fix
Node.js shipped v22.23.0, v24.17.0 and v26.3.1 on June 18, fixing 12 CVEs including two high-severity WebCrypto and TLS flaws. Node 20, EOL since April, gets no patch.
CISA Adds the First-Ever Splunk Flaw to Its KEV Catalog, an Unauthenticated File-Write Bug in a PostgreSQL Sidecar Now Exploited in the Wild
CVE-2026-20253, a CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar, became the first Splunk bug on CISA's KEV list, with federal agencies ordered to patch by June 21.
F5 Ships Out-of-Band NGINX Patches for Two Critical Flaws, Including a 9.2 HTTP/3 Use-After-Free Reachable by Unauthenticated Attackers
F5 patched CVE-2026-42530, a CVSS 9.2 use-after-free in NGINX's HTTP/3 module, alongside a second 9.2 buffer overflow. Neither is known to be exploited.
Jenkins Patches High-Severity Deserialization Flaw CVE-2026-53435 That Turns a config.xml Submission Into Controller-Side Code Execution
Jenkins fixed CVE-2026-53435, an 8.8-rated deserialization flaw letting an attacker-controlled config.xml impersonate users and reach the Script Console for code execution on the controller.
CISA Flags Exploited SolarWinds Serv-U Crash Flaw CVE-2026-28318 in KEV as a Single Deflate Header Downs File-Transfer Servers
CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request using a Content-Encoding: deflate header. CISA added it to the KEV catalog on June 5, 2026 amid active exploitation; SolarWinds shipped a hotfix on June 6.