Aggregator
DragonForce
You must login to view this content
DragonForce
You must login to view this content
Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz
DragonForce
You must login to view this content
CVE-2026-7852 | Limatek LimRAD NAC prior 5.5.7.3.9 unrestricted upload (EUVD-2026-36237)
CVE-2026-50568 | Fission up to 1.24.x pkg/utils/utils.go resolution of path (GHSA-r5jh-q2mw-gcx4 / EUVD-2026-36072)
CVE-2026-45062 | dunglas frankenphp prior 1.12.3 CGI Path Splitting unicode encoding (EUVD-2026-36075)
CVE-2026-46642 | jgraph drawio up to 29.7.11 cross site scripting (GHSA-fqhg-287p-c6vf / EUVD-2026-36077)
CVE-2026-46654 | Plonky3 up to 0.4.2/0.5.2 cryptographic primitive risky implementation (GHSA-vj64-rjf3-w3v7 / EUVD-2026-36119)
CVE-2026-5497 | vLLM up to 0.18.x OpenAI-compatible Chat Completions API VideoMediaIO.load_base64 resource consumption (EUVD-2026-36217)
CVE-2026-53901 | cerebrate up to 1.36 add params dynamically-determined object attributes (EUVD-2026-36216)
CVE-2026-53465 | ImageMagick up to 7.1.2-24 SF3 Encoder heap-based overflow (GHSA-44cp-c3ww-9rv5 / EUVD-2026-36192)
CVE-2026-53737 | saas.group Juicer up to 1.12.18 Setting cross site scripting (EUVD-2026-36138)
DragonForce
You must login to view this content
CVE-2026-41694 | Vmware Spring Security up to 7.0.5 SAML Response signature verification (CNNVD-202606-2873)
CVE-2026-41696 | Vmware Spring Data MongoDB up to 5.0.5 String data query logic injection (CNNVD-202606-2872)
CVE-2026-41003 | Vmware Spring Security up to 7.0.5 RelyingPartyRegistration cross site scripting (CNNVD-202606-2875)
CVE-2026-41008 | Vmware Spring Security/Spring Authorization Server Authorization Endpoint request_uri redirect (CNNVD-202606-2874)
CISA orders federal agencies to “patch smarter”
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive that will change how the US federal government approaches vulnerability management. The directive arrives as the patching problem has become nearly unmanageable, driven by a surge in newly published vulnerabilities and by AI tools that are accelerating both security research and exploit development on the attacker side. Towards risk-based vulnerability management BOD 26-04 introduces a framework that allow federal civilian Executive … More →
The post CISA orders federal agencies to “patch smarter” appeared first on Help Net Security.