An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take administrative control of exposed servers.
The flaws, tracked as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, affect multiple Artifactory release branches and create a...
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems.
The flaws affect Dell Secure Connect Gateway 5.0 Appliance...
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly.
FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise...
SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances.
The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands.
The...
ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.
The company published...
Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images.
The first flaw, tracked as CVE-2026-75604, affects Next.js applications that use either the Pages Router or the App Router...
Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk Connect for Kafka.
The most severe issue, tracked as CVE-2026-76404, is a critical remote code execution vulnerability with...
Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could allow attackers to bypass authentication and take over user accounts.
The findings highlight the persistent security risks created by XML...
BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper controls.
Tracked as CVE-2026-40144 and CVE-2026-40145, the flaws affect all versions of...
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.
The updates were released on August 17, 2026, and include macOS...