LIVE FEED
Subscribe
//

Category: Vulnerabilities

Vulnerabilities Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
CRITICAL Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse

F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…

by Robbie · 4 weeks ago
Vulnerabilities 7-Zip 26.02 Patches Heap Overflow RCE Flaw in XZ Archive Handling
HIGH Vulnerabilities

7-Zip 26.02 Patches Heap Overflow RCE Flaw in XZ Archive Handling

7-Zip has fixed a remote code execution vulnerability in its XZ decompression code that can be triggered by opening a maliciously crafted…

by Robbie · 4 weeks ago
Vulnerabilities WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately
CRITICAL Vulnerabilities

WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately

Two chained flaws in WordPress Core allow unauthenticated remote code execution against stock installs, and public proof-of-concept exploits are now circulating with…

by Robbie · 4 weeks ago
Vulnerabilities Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates
CRITICAL Vulnerabilities

Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates

A critical WordPress core vulnerability, dubbed wp2shell, allowed unauthenticated attackers to execute code on any 6.9 or 7.0 site with a single…

by Robbie · 4 weeks ago
Vulnerabilities Ernst & Young Discloses Breach Tied to Third-Party Support Ticket System
MEDIUM Vulnerabilities

Ernst & Young Discloses Breach Tied to Third-Party Support Ticket System

A compromised support platform used by EY's IT staff exposed client documents containing tax and financial information, with unauthorized access dating back…

by Robbie · 4 weeks ago
Vulnerabilities HollowByte: 11-Byte Payload Can Bloat OpenSSL Server Memory to Exhaustion
MEDIUM Vulnerabilities

HollowByte: 11-Byte Payload Can Bloat OpenSSL Server Memory to Exhaustion

An unauthenticated denial-of-service flaw dubbed HollowByte lets attackers exploit how OpenSSL handles TLS handshake length headers, forcing servers to allocate memory that…

by Robbie · 4 weeks ago
Vulnerabilities CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog
CRITICAL Vulnerabilities

CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog

A critical deserialization bug in on-premises SharePoint Server has joined at least three other actively exploited flaws under active attack, with CISA…

by Robbie · 4 weeks ago
Vulnerabilities Ransomware Attack on Coca-Cola’s Fairlife Halts US Dairy Production
HIGH Vulnerabilities

Ransomware Attack on Coca-Cola’s Fairlife Halts US Dairy Production

Coca-Cola disclosed in an SEC filing that a ransomware intrusion at its Fairlife dairy subsidiary forced a temporary suspension of US production,…

by Robbie · 4 weeks ago
Vulnerabilities F5 Issues Emergency Patches for Critical NGINX Flaw, Seven Other Bugs
CRITICAL Vulnerabilities

F5 Issues Emergency Patches for Critical NGINX Flaw, Seven Other Bugs

F5 has released an out-of-band update fixing eight vulnerabilities across NGINX and BIG-IP, including a critical, unauthenticated heap buffer overflow rated 9.2…

by Robbie · 4 weeks ago
Vulnerabilities Old Microsoft-Signed UEFI Shims Let Attackers Bypass Secure Boot
HIGH Vulnerabilities

Old Microsoft-Signed UEFI Shims Let Attackers Bypass Secure Boot

ESET found 11 outdated, still-trusted Microsoft-signed shim bootloaders that could let attackers run untrusted code during boot and plant bootkits, prompting Microsoft…

by Robbie · 4 weeks ago
Vulnerabilities Revoked UEFI Shim Bootloaders Left Secure Boot Wide Open for Years
HIGH Vulnerabilities

Revoked UEFI Shim Bootloaders Left Secure Boot Wide Open for Years

Nearly a dozen vulnerable UEFI shim bootloaders remained trusted on systems long after being flagged and revoked, giving attackers a viable path…

by Robbie · 4 weeks ago
Vulnerabilities Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover
CRITICAL Vulnerabilities

Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover

Zoom has disclosed a critical, internally discovered vulnerability in its Windows desktop client, VDI client, and Meeting SDK that could let an…

by Robbie · 4 weeks ago
1 4 5 6 13

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.