Vulnerability

GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks

GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function.…

1 week ago

CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog, warning…

2 weeks ago

CopyEscape Docker Vulnerability Lets Malicious Containers Overwrite Host Files and Gain Root

A newly disclosed Docker vulnerability, tracked as CVE-2026-17106 and nicknamed "CopyEscape," allows malicious containers to overwrite files on the host…

2 weeks ago

Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval

RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira,…

2 weeks ago

CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The…

3 weeks ago

CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks

CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the…

3 weeks ago

Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks

A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers…

3 weeks ago

Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System

Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to compromise vulnerable Security…

3 weeks ago

TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks

TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as…

3 weeks ago

Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated…

3 weeks ago