CVE-2025-21589: Critical Juniper Session Smart Flaw Enables Unauthenticated Full Admin Takeover
CVE-2025-21589 Product: Juniper Session Smart Router (SSR) / Session Smart Conductor / WAN Assurance Managed RouterVulnerability Type:…
continue reading..
eScan Antivirus Update Server Compromised in Supply Chain Attack, Malware Distributed to Users
On January 20, a supply chain compromise was identified involving the eScan antivirus product developed by MicroWorld…
continue reading..
Trusted Tool Turned Trojan: EmEditor Official Installer Hijacked in Sophisticated Supply-Chain Attack
In late December 2025, a sophisticated software supply chain compromise was discovered affecting EmEditor, a widely-used Windows…
continue reading..
CVE-2026-1470: Critical n8n Flaw Allows Workflow Expressions to Trigger Full System Takeover
CVE-2026-1470 High-Level Risk Statement A critical weakness exists in the way n8n evaluates user-defined expressions inside workflows.…
continue reading..
CVE-2026-24779: High-Risk SSRF Flaw in vLLM Lets Attackers Slip Past Host Restrictions Using Crafted URLs
CVE-2026-24779 — vLLM SSRF via Host Restriction Bypass CVE: CVE-2026-24779Product: vLLMAffected Versions: vLLM versions prior to 0.14.1Vulnerability…
continue reading..
CVE-2026-24770: Critical RAGFlow MinerU Zip Slip Flaw Enables Remote Code Execution via Malicious ZIP Uploads
CVE-2026-24770 CVE ID: CVE-2026-24770Product: RAGFlow – MinerU ingestion componentAffected Versions: All versions ≤ 0.23.1Vulnerability Type: Zip Slip…
continue reading..
CVE-2026-24765: Silent PHPUnit Test Runs Can Turn CI Pipelines into a Code-Execution Trap
CVE-2026-24765 – Unsafe Deserialization Leading to Code Execution in PHPUnit CVE ID: CVE-2026-24765Component: PHPUnit – PHPT Code…
continue reading..
CVE-2026-24747: “Trusted” PyTorch Model Files Can Trigger Memory Corruption and Lead to Remote Code Execution
CVE-2026-24747 – PyTorch Memory Corruption via Pickle Leading to Potential RCE CVE ID: CVE-2026-24747Severity: HighCVSS v3.1 Score:…
continue reading..
CVE-2026-24741: High-Severity ConvertX Flaw Lets Attackers Delete Arbitrary Server Files via Simple Path Traversal
Vulnerability Overview CVE ID: CVE-2026-24741Product: ConvertXAffected Versions: All versions prior to 0.17.0Fixed Version: 0.17.0 and laterSeverity: HighCVSS…
continue reading..
