Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks.
The new...
The OpenVPN project has shipped version 2.7.7, a security-focused release that patches seven distinct vulnerabilities spanning the software's core reliability layer and its Windows-specific service components.
The update, released on September 3, 2026, addresses issues ranging from denial-of-service conditions to...
N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server.
The update, identified as build 2026.3.1.14, was issued for on-premises N-central deployments. N-able...
Two critical vulnerabilities in PaperCut servers, CVE-2026-81578 and CVE-2026-82078, are being actively exploited, allowing attackers to execute commands, steal credentials, and potentially create privileged accounts within victim networks.
Recent reports from Arctic Wolf Threat Intelligence indicate that these vulnerabilities are...
A newly disclosed PostgreSQL vulnerability, tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access to execute arbitrary code on database servers.
The flaw in PostgreSQL logical decoding existed for roughly 12 years and has now been...
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password...
Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover.
MikroTik confirmed on September 3, 2026, that it...
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available.
Dutch e-commerce security firm Sansec disclosed the...
Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible.
The update addresses multiple undisclosed security issues affecting Plex Media Server versions 1.43.2 and earlier,...
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices.
The flaws, tracked as CVE-2026-18167 and...