Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration (CVE-2026-0234)

CVE number = CVE-2026-0234 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during

Read More
NewsSecurity Vulnerabilities

Ongoing campaign exploiting vulnerabilities in Cisco VPN devices

– An attacker attributed to ArcaneDoor campaign has exploited CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363 to install a sophisticated bootkit for persistent stealthy access to affected devices.

Read More
NewsSecurity Vulnerabilities

DriveLock Directory Traversal Information Disclosure Vulnerability (CVE-2026-5492)

– This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock.

Read More
NewsSecurity NewsSecurity Vulnerabilities

Supply Chain Compromise Impacts Axios Node Package Manager​

– The Cybersecurity and Infrastructure Security Agency (CISA) released an alert to provide guidance in response to the software supply chain compromise of the Axios node package manager (npm). Axios is an HTTP client for JavaScript that developers commonly use in Node.js and browser environments. 

Read More
NewsSecurity Vulnerabilities

Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-40688)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiWeb. Authentication is required to exploit this vulnerability.

Read More
NewsSecurity Vulnerabilities

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability (CVE-2026-25203)

CVE number = CVE-2026-25203 This vulnerability allows local attackers to escalate privileges on affected installations of Samsung MagicINFO 9 Server.

Read More
NewsSecurity Vulnerabilities

Linux Kernel ETS Scheduler Race Condition Local Privilege Escalation Vulnerability (CVE-2025-71066)

– This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel.

Read More
NewsSecurity Vulnerabilities

Acrobat Reader Improperly Controlled Modification of Object Prototype Attributes vulnerability (CVE-2026-34621)

– Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’) vulnerability.

Read More
NewsSecurity Vulnerabilities

Critical severity vulnerability affecting CPython (CVE-2026-6100)

– Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used.

Read More
NewsSecurity Vulnerabilities

Apache dolphinscheduler sensitive information disclosure (CVE-2023-48796)

– Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.

Read More