GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the jsonArrayContains filter function.
The issue can allow attackers to manipulate database queries via publicly accessible OGC WMS and WFS services and, under dangerous...
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog, warning that the flaw is being exploited in attacks.
The issue, tracked as CVE-2026-68820, is a use-after-free vulnerability affecting the Windows...
A newly disclosed Docker vulnerability, tracked as CVE-2026-17106 and nicknamed "CopyEscape," allows malicious containers to overwrite files on the host machine and, in certain configurations, achieve full root code execution.
The flaw was discovered by the Imperva Red Team and...
RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services.
Atlassian addressed the reported URL-based issue on the server side after responsible disclosure, with...
The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The vulnerability, tracked as CVE-2026-63077, can let an unauthenticated attacker run code remotely on vulnerable TeamCity On-Premises servers.
CISA added the...
CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the flaw affects N-central servers running versions earlier than 2026.3.1.7.
N-central is a remote monitoring and management platform widely used by...
A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and potentially escalate the attack to remote code execution. The issue affects Gitea versions from 1.22.1 through 1.27.0 and...
Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to compromise vulnerable Security Management environments fully.
This issue affects both Security Management Server and Multi-Domain Security Management Server deployments across several Check Point...
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition or achieve remote code execution on vulnerable devices under...
N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated attackers to gain full administrative, or “god-mode,” access to the RMM console.
This issue affects all currently supported N-central versions,...