CVE-2026-28363: Critical OpenClaw safeBins Bypass Enables Approval-Free Command Execution via GNU Option Abuse
OpenClaw safeBins Allowlist Bypass – Approval-Free Execution CVE ID: CVE-2026-28363Product: OpenClawComponent: tools.exec.safeBinsAffected Versions: All versions prior to…
continue reading..
CVE-2026-28372: Critical Flaw in GNU inetutils Telnetd Lets Local Users Escalate to Root Without Authentication
GNU inetutils telnetd Privilege Escalation Vulnerability Executive Summary A privilege escalation issue was identified in GNU inetutils…
continue reading..
CVE-2026-3277: PowerShell Universal Exposes OIDC Client Secret in Cleartext, Enabling Service Impersonation Risks
CVE-2026-3277 Product: PowerShell UniversalVendor: DevolutionsVulnerability Type: Cleartext Storage of Sensitive InformationCWE: CWE-312CVSS v4.0: 6.8Severity: MediumAttack Vector: Local…
continue reading..
Critical Security Alert: Multiple Zero-Day-Style Flaws in n8n Could Allow Full Server Takeover — Immediate Patching Strongly Advised
Product Overview Product: n8nVendor: n8n GmbHType: Workflow Automation & Integration PlatformCore Technology: Node.js (TypeScript), Express backend, SQLite/PostgreSQL,…
continue reading..
CVE-2026-27812: Sub2API Password Reset Flaw Allows Account Takeover via Host Header Manipulation
Sub2API Password Reset Poisoning via Host Header Manipulation CVE ID: CVE-2026-27812Product: Sub2APIAffected Versions: Versions prior to 0.1.85Fixed…
continue reading..
CVE-2026-27966: Critical Langflow CSV Agent Flaw Exposes Servers to Unauthenticated Remote Code Execution
Langflow CSV Agent Remote Code Execution via hardcoded allow_dangerous_code=True A critical remote code execution vulnerability was identified…
continue reading..
CVE-2026-2441: Actively Exploited Chrome Zero-Day Enables Remote Code Execution via Crafted Web Pages
Vulnerability Overview CVE ID: CVE-2026-2441Component Affected: Google Chrome / Chromium (Blink rendering engine – CSS handling)Vulnerability Type:…
continue reading..
CVE-2026-3202: Wireshark NTS-KE Parser Flaw Triggers Crash, Disrupting Network Analysis Workflows
Wireshark NTS-KE Dissector Crash – Denial of Service CVE ID: CVE-2026-3202Affected Product: WiresharkAffected Versions: 4.6.0 through 4.6.3Fixed…
continue reading..
CVE-2026-27597: Critical Enclave VM Sandbox Escape Enables Full Remote Code Execution on Host Systems
CVE-2026-27597 CVE ID: CVE-2026-27597Product: Enclave VM (@enclave-vm/core)Vulnerability Type: JavaScript Sandbox Escape → Remote Code Execution (RCE)Affected Versions:…
continue reading..
