CVE-2025-53967: Unauthenticated Command Injection Leading to Full Remote Code Execution in Framelink Figma MCP Server
Vulnerability Overview Executive Summary A high-severity command injection vulnerability exists in the Framelink Figma MCP Server. Due…
continue reading..
CVE-2026-0756: Unauthenticated Remote Code Execution via Command Injection in github-kanban-mcp-server
Vulnerability Summary CVE ID: CVE-2026-0756Component: github-kanban-mcp-server (@sunwood-ai-labs/github-kanban-mcp-server)Vulnerability Type: OS Command InjectionAttack Class: Unauthenticated Remote Code ExecutionSeverity: CriticalCVSS…
continue reading..
CVE-2026-0764: Critical Unauthenticated Deserialization RCE in GPT Academic Leading to Root-Level System Compromise
Top-Level Summary Vulnerability Background This issue arises because the GPT Academic application accepts serialized data uploaded by…
continue reading..
CVE-2026-0768: Unauthenticated Langflow RCE Enables Full Server Takeover
CVE-2026-0768 – Langflow Unauthenticated Remote Code Execution CVE ID: CVE-2026-0768Product: LangflowVulnerability Type: Unauthenticated Remote Code Execution (RCE)Severity:…
continue reading..
CVE-2026-0759: Critical Unauthenticated Remote Code Execution in Katana Network Dev Kit
CVE: CVE-2026-0759Severity: CriticalCVSS v3.1 Score: 9.8 (Critical – unauthenticated remote code execution)Type: OS Command Injection → Unauthenticated…
continue reading..
CVE-2026-24061: Unauthenticated Remote Root Access via Legacy Telnet Authentication Bypass
CVE-2026-24061 — Legacy Telnet Authentication Bypass CVE ID: CVE-2026-24061Vulnerability Type: Authentication Bypass / Improper Input HandlingSeverity: CriticalCVSS…
continue reading..
A SmarterMail Patch Was Reverse-Engineered — Now Admin Accounts Are at Risk
SmarterMail Zero-Day: Why a January Patch Turned Into an Urgent Security Event Security researchers issued an urgent…
continue reading..
Silent Session Hijack: Malicious Chrome Extensions Undermining Enterprise HR and ERP Security
Executive summary A targeted browser-based attack campaign leveraged malicious Google Chrome extensions to compromise authenticated sessions of…
continue reading..
Operation Nomad Leopard: How a Single Email Opened the Door to Silent Government Espionage
Executive Summary Operation Nomad Leopard is a targeted cyber-espionage campaign focused on Afghan government personnel. The attack…
continue reading..
