-
SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability. This flaw could allow attackers to gain unauthorized access to affected systems by exploiting weaknesses in SAML-based single sign-o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-ser…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the se…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of act…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they are publicly disclosed, according to VulnCheck’s State of Exploitation report for the first half of…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes for seven critical-severity flaws that affect core components of the browser. The new versions are …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitLab has released security updates for both the Community Edition (CE) and Enterprise Edition (EE), addressing 13 vulnerabilities that could allow unauthorized data exposure, tampering with CI/CD pipelines, bypassing protected branches, and denial-of…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Node.js Project has released security updates for the active Node.js versions 22.x, 24.x, and 26.x, addressing 11 vulnerabilities. These vulnerabilities range from high-severity issues, such as HTTP/2 memory corruption and permission-bypass flaws, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could allow malicious instructions hidden within documents to alter Copilot-generated content and sprea…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a serious vulnerability in Mozilla Firefox’s JavaScript engine. Security researchers at Nebula Secu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


