CVE-2026-1999: Critical Authorization Bypass in GitHub Enterprise Server Allows Unauthorized Auto-Merges
GitHub Enterprise Server – Authorization Bypass via Auto-Merge CVE ID: CVE-2026-1999Product: GitHub Enterprise Server (GHES)Vulnerability Type: Authorization…
continue reading..
OpenClaw Critical Vulnerabilities: CVE-2026-27002, CVE-2026-27001 & CVE-2026-25474 — Container Escape, Prompt Injection & Webhook Authentication Bypass
OpenClaw — Product Overview OpenClaw is a locally hosted, tool-enabled AI assistant that can interact with the…
continue reading..
CVE-2026-27013: Critical Stored XSS Flaw in Fabric.js SVG Export Exposes Applications to Remote Script Injection
Vulnerability Summary Field Value CVE ID CVE-2026-27013 Affected Product Fabric.js (npm package: fabric) Affected Versions All versions…
continue reading..
CVE-2026-25926: Notepad++ Unsafe Search Path Flaw Enables Silent Code Execution via Explorer Hijack
Notepad++ – Unsafe Search Path Leading to Arbitrary Code Execution CVE ID: CVE-2026-25926Affected Product: Notepad++ (Windows)Vulnerability Type:…
continue reading..
CVE-2026-1435: Critical Session Fixation Flaw in Graylog Web Interface Enables Silent Account Takeover
CVE-2026-1435 — Graylog Web Interface Field Value CVE ID CVE-2026-1435 Affected Product Graylog Web Interface (confirmed in…
continue reading..
CVE-2026-26988 & CVE-2026-26990: Critical SQL Injection Flaws Rock LibreNMS — Public PoC Raises Urgent Upgrade Warning
LibreNMS — Product Overview Product: LibreNMSType: Open-source network monitoring systemTechnology Stack: PHP application with MySQL/MariaDB backendAffected Area:…
continue reading..
CVE-2026-23595: Critical Authentication Bypass Lets Attackers Create Admin Accounts in HPE Aruba Private 5G Core
Unauthenticated API flaw exposes core network control — full administrative takeover possible from adjacent network access Authentication…
continue reading..
CVE-2026-2439: Critical Session ID Flaw in Concierge::Sessions Opens Door to Remote Account Takeover
Concierge::Sessions (Perl) — Predictable Session IDs CVE ID: CVE-2026-2439Affected Component: Concierge::Sessions (Concierge::Sessions::Base)Affected Versions: 0.8.1 through 0.8.4Fixed Version:…
continue reading..
CVE-2026-25903: Apache NiFi Authorization Bypass Lets Low-Privilege Users Modify Restricted Dataflows
Apache NiFi – Missing Authorization on Restricted Component Updates CVE ID: CVE-2026-25903Product: Apache NiFiAffected Versions: 1.1.0 through…
continue reading..
