Vulnerability News

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a…

4 days ago

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the "Noble Numbat" long-term support release, delivering…

5 days ago

GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution

GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that…

5 days ago

Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection

Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could…

5 days ago

CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks…

6 days ago

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code…

6 days ago

Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit…

7 days ago

MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks

A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7…

7 days ago

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely…

7 days ago

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able's N-central remote monitoring and management platform to…

7 days ago