Vulnerabilities
120 articles RSS
OpenSSH 10.5 Fixes ssh-agent Locking Bypass and Two Other Flaws, Citing AI-Assisted Bug Reports for a Faster Release Cadence
OpenSSH 10.5 patches a locking bypass in ssh-agent and two other flaws, and the project says a surge in AI-assisted vulnerability reports is pushing it toward faster, on-demand security releases.
GitLab Patches 13 Security Flaws, Including CI/CD Pipeline Tampering and a Duo Code Review Prompt-Injection Bug
GitLab's 19.2.1, 19.1.3, and 19.0.5 patch release fixes 13 vulnerabilities, including three high-severity flaws and a prompt-injection bug in Duo Code Review.
HashiCorp Patches Critical CVSS 10.0 Cross-Tenant Credential Bug in Terraform MCP Server
A maximum-severity flaw let one user's Terraform token be reused for other users' requests in stateless HTTP mode; two related bugs also patched in version 1.1.0.
Node.js Ships Twice-Delayed July Security Release Patching 11 CVEs as Node 18 and 20 Sit Fully Unpatched
Node.js shipped 11 CVE fixes across three High-severity HTTP/2 and Permission Model bugs on July 29, after two delays, while EOL versions 18 and 20 get nothing upstream.
CISA Orders Federal Agencies to Patch Actively Exploited N-able N-central Authentication Bypass
CISA gave federal agencies until August 6 to patch CVE-2026-18577, an N-central auth bypass exploited in the wild since July 31 that grants attackers admin access to the RMM console.
Rails Patches Critical Active Storage Flaw That Lets Unauthenticated Attackers Read Secrets and Escalate to RCE
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
SQLite's Official Vulnerability Page Brands Six 'Critical' CVEs as AI Hallucinations After NVD Rejects Them
SQLite's own CVE tracker and the National Vulnerability Database both rejected six reports as AI-hallucinated after a JFrog researcher found the underlying code and PoCs didn't exist or didn't work.
Cisco FMC Static-Credential Zero-Day Hits CISA's KEV Catalog With August 1 Federal Patch Deadline
CISA added a Cisco Firewall Management Center static-credential flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by August 1.
Critical Gitea Flaw Lets a Self-Registered Account Turn a Git Patch Into Remote Code Execution
A critical Gitea vulnerability lets a repository writer convert a crafted patch into a live Git hook and run shell commands as the service account.
STAR Labs Researcher Uses AI to Turn a Linux Traffic-Control Race Condition Into a Root Exploit
A Singapore researcher disclosed CVE-2026-53264, an AI-assisted Linux kernel use-after-free that escalates local access to root on CentOS Stream 9.
JetBrains Patches Critical Unauthenticated RCE in TeamCity On-Premises, Its Third Distinct Vulnerability Batch This Summer
JetBrains fixed CVE-2026-63077, a 9.8-severity flaw letting unauthenticated attackers run OS commands on TeamCity servers via the agent polling protocol.
Over 24,650 Internet-Exposed Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
Researchers found 24,650 of 36,872 exposed server management interfaces disclose crackable password hashes before login, via a 2013 IPMI flaw still unpatched by Dell.