Category: Vulnerabilities
Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…
7-Zip 26.02 Patches Heap Overflow RCE Flaw in XZ Archive Handling
7-Zip has fixed a remote code execution vulnerability in its XZ decompression code that can be triggered by opening a maliciously crafted…
WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately
Two chained flaws in WordPress Core allow unauthenticated remote code execution against stock installs, and public proof-of-concept exploits are now circulating with…
Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates
A critical WordPress core vulnerability, dubbed wp2shell, allowed unauthenticated attackers to execute code on any 6.9 or 7.0 site with a single…
Ernst & Young Discloses Breach Tied to Third-Party Support Ticket System
A compromised support platform used by EY's IT staff exposed client documents containing tax and financial information, with unauthorized access dating back…
HollowByte: 11-Byte Payload Can Bloat OpenSSL Server Memory to Exhaustion
An unauthenticated denial-of-service flaw dubbed HollowByte lets attackers exploit how OpenSSL handles TLS handshake length headers, forcing servers to allocate memory that…
CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog
A critical deserialization bug in on-premises SharePoint Server has joined at least three other actively exploited flaws under active attack, with CISA…
Ransomware Attack on Coca-Cola’s Fairlife Halts US Dairy Production
Coca-Cola disclosed in an SEC filing that a ransomware intrusion at its Fairlife dairy subsidiary forced a temporary suspension of US production,…
F5 Issues Emergency Patches for Critical NGINX Flaw, Seven Other Bugs
F5 has released an out-of-band update fixing eight vulnerabilities across NGINX and BIG-IP, including a critical, unauthenticated heap buffer overflow rated 9.2…
Old Microsoft-Signed UEFI Shims Let Attackers Bypass Secure Boot
ESET found 11 outdated, still-trusted Microsoft-signed shim bootloaders that could let attackers run untrusted code during boot and plant bootkits, prompting Microsoft…
Revoked UEFI Shim Bootloaders Left Secure Boot Wide Open for Years
Nearly a dozen vulnerable UEFI shim bootloaders remained trusted on systems long after being flagged and revoked, giving attackers a viable path…
Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover
Zoom has disclosed a critical, internally discovered vulnerability in its Windows desktop client, VDI client, and Meeting SDK that could let an…