Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory.
The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0 through 3.0.23 and require a...
Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the "Noble Numbat" long-term support release, delivering a fresh installation image packed with the latest security patches, bug fixes, and an upgraded hardware enablement stack built...
GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that could enable arbitrary file reads and credential theft.
A separate high-severity issue in GitLab Enterprise Edition could allow authenticated attackers...
Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored cross-site scripting, authorization bypass, and SQL injection in certain configurations.
The vulnerabilities were disclosed on September 8, 2026....
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026.
CVE-2026-19490 affects Citrix NetScaler ADC and...
Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls.
Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor...
A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48...
A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to zero-click attacks.
The flaw, tracked as CVE-2026-85061 and GitHub Security Advisory GHSA-jrc7-96c5-q579, affects maplibre-gl versions 6.4.0 and...
Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices.
The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should...
The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able's N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets.
The vulnerability, tracked as...