Vulnerabilities
120 articles RSS
DifyTap: Four Authorization Flaws Let Attackers Silently Wiretap AI Chats Across Tenants on a Platform Powering Over 1 Million Apps
Zafran Security disclosed four authorization flaws in the open-source LLMOps platform Dify, including two critical bugs that let an attacker redirect another tenant's AI conversations to an attacker-controlled endpoint.
CISA Adds Max-Severity Joomla Content Editor Flaw CVE-2026-48907 to KEV as Attackers Drop Web Shells via Rogue Editor Profiles
An unauthenticated RCE in the JCE extension, scored CVSS 4.0 10.0, is being exploited to plant web shells. CISA set a June 19 federal deadline.
Node.js Patches 12 CVEs in June Security Release, Two Rated High, as End-of-Life Node 20 Is Left Without a Fix
Node.js shipped v22.23.0, v24.17.0 and v26.3.1 on June 18, fixing 12 CVEs including two high-severity WebCrypto and TLS flaws. Node 20, EOL since April, gets no patch.
CISA Adds the First-Ever Splunk Flaw to Its KEV Catalog, an Unauthenticated File-Write Bug in a PostgreSQL Sidecar Now Exploited in the Wild
CVE-2026-20253, a CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar, became the first Splunk bug on CISA's KEV list, with federal agencies ordered to patch by June 21.
F5 Ships Out-of-Band NGINX Patches for Two Critical Flaws, Including a 9.2 HTTP/3 Use-After-Free Reachable by Unauthenticated Attackers
F5 patched CVE-2026-42530, a CVSS 9.2 use-after-free in NGINX's HTTP/3 module, alongside a second 9.2 buffer overflow. Neither is known to be exploited.
Jenkins Patches High-Severity Deserialization Flaw CVE-2026-53435 That Turns a config.xml Submission Into Controller-Side Code Execution
Jenkins fixed CVE-2026-53435, an 8.8-rated deserialization flaw letting an attacker-controlled config.xml impersonate users and reach the Script Console for code execution on the controller.
CISA Flags Exploited SolarWinds Serv-U Crash Flaw CVE-2026-28318 in KEV as a Single Deflate Header Downs File-Transfer Servers
CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request using a Content-Encoding: deflate header. CISA added it to the KEV catalog on June 5, 2026 amid active exploitation; SolarWinds shipped a hotfix on June 6.
ShinyHunters Exploited an Oracle PeopleSoft Zero-Day for Two Weeks Before Disclosure as CVE-2026-35273 Lands on CISA's KEV Catalog
CVE-2026-35273, a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft PeopleTools, was exploited as a zero-day by UNC6240 before Oracle shipped mitigations and CISA set a June 15 federal deadline.
ServiceNow Patches an Unauthenticated API Endpoint That Let Customer Instance Tables Be Queried Without Credentials
ServiceNow fixed a REST API endpoint that shipped without authentication, after confirming a subset of customer instances were queried. It has not assigned a CVE.
Microsoft Ships Its Largest Patch Tuesday on Record, Led by a Wormable CVSS 9.8 Windows Kernel Flaw
June 2026's update tops the previous record of 177 CVEs and includes CVE-2026-45657, a wormable 9.8 kernel use-after-free.
Check Point Patches Critical VPN Zero-Day CVE-2026-50751 After a Month of Exploitation Tied to a Qilin Ransomware Affiliate
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.
Critical Everest Forms Pro WordPress Flaw CVE-2026-3300 Exploited for Two Months as Wordfence Blocks 29,300 Attacks
An unauthenticated PHP code-injection bug in the Everest Forms Pro plugin, patched in March, has been exploited since April 13 to plant rogue administrator accounts on WordPress sites.