Vulnerability

Critical Capacitor Flaw Lets Malicious Links Access App Data and Native Features

A critical vulnerability in Capacitor for Android and iOS could let a malicious link opened inside an affected mobile app…

4 days ago

Node.js ImageResponse Implementation Vulnerability Enables Remote Code Execution

A critical vulnerability in Next.js could allow remote code execution in applications that use the Node.js implementation of ImageResponse from…

5 days ago

Critical MikroTik RouterOS Flaw Lets Unauthenticated Attackers Execute Code as Root

A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute arbitrary code with root-level privileges or trigger…

5 days ago

CopyEscape Docker Flaw Lets Malicious Containers Overwrite Host Files and Gain Root Access

A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution…

5 days ago

AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access

Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory…

6 days ago

Unsloth Studio RCE Flaw Lets Malicious Hugging Face Models Execute Code

A now-patched vulnerability in Unsloth Studio allowed a malicious Hugging Face model repository to execute Python code when a user…

6 days ago

Octopus Server Flaw Lets Authenticated Users Execute Code Through Insecure JSON Deserialization

Octopus Deploy has disclosed a high-severity vulnerability in Octopus Server that could allow authenticated users to execute arbitrary code on…

6 days ago

Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a critical zero-day vulnerability that it says may have been…

1 week ago

PHP Fixed a Bug That Could Send Your Login Credentials to the Wrong Server

PHP has fixed a security flaw that could expose login credentials, cookies, and proxy authentication data to an unintended server…

1 week ago

Sudo Security Vulnerability Lets Attackers Escalate Privileges

A high-severity security vulnerability in Sudo could allow local attackers to bypass time-based access restrictions and run commands with elevated…

2 weeks ago