CVE-2026-27607: RustFS Upload Policy Bypass Opens Door to Storage Abuse and Unauthorized Object Writes
CVE-2026-27607 CVE ID: CVE-2026-27607Product: RustFS (S3-compatible object storage)Vulnerability Type: Policy Bypass / Upload Constraint BypassAffected Versions: 1.0.0-alpha.56…
continue reading..
CVE-2026-2624: Critical Authentication Bypass in Antikor NGFW Exposes Firewalls to Full Remote Takeover
CVE-2026-2624 — Antikor NGFW Authentication Bypass CVE: CVE-2026-2624Product: ePati Cyber Security Antikor Next Generation Firewall (NGFW)Affected Versions:…
continue reading..
CVE-2025-62878: Critical Kubernetes Storage Flaw Lets Attackers Overwrite Host Files and Seize Cluster Control
CVE-2025-62878 Product: Rancher Local Path ProvisionerVulnerability Type: Path Traversal → Arbitrary Host File WriteSeverity: CriticalCVSS v3.1: 10.0…
continue reading..
CVE-2026-20129 & CVE-2026-20127: Critical Authentication Flaws Expose Cisco Catalyst SD-WAN to Full Network Takeover
Product Details Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller are core components of Cisco’s SD-WAN…
continue reading..
CVE-2026-27464: Metabase Flaw Lets Low-Privilege Users Steal Database Credentials via Notification Templates
CVE-2026-27464 — Metabase Credential Exposure Vulnerability CVE Name: Credential Extraction via Notification Template EvaluationCVE ID: CVE-2026-27464CVSS v3.1…
continue reading..
CVE-2026-27471: Critical ERPNext Access Control Flaw Exposes Sensitive Business Documents to Remote Attackers
CVE-2026-27471 Product: ERPNext (Open Source ERP Tool)Vulnerability Type: Access Control Bypass / Unauthorized Document AccessAttack Vector: Remote…
continue reading..
CRITICAL MOODLE RCE ALERT: CVE-2026-26045 & CVE-2026-26046 Enable Full Server Takeover Through Backup Restore and Admin Command Injection
Moodle Security Advisory Product: Moodle LMSVendor: Moodle Pty LtdAffected Components: Impact: Remote Code Execution (RCE), Command InjectionRisk…
continue reading..
CVE-2026-27487: OpenClaw CLI Command Injection Flaw Enables Local System Compromise on macOS
CVE-2026-27487 Product: OpenClaw CLI (macOS keychain integration)Vulnerability Type: OS Command Injection (CWE-78)CVSS v3.1 Score: 7.6 (High)Severity: HighAttack…
continue reading..
CVE-2026-27168: Critical Heap Overflow in SAIL Image Library Opens Door to Remote Code Execution
CVE-2026-27168 CVE ID: CVE-2026-27168Product: SAIL (Simple and Flexible Image Library)Affected Component: XWD image codec (sail-codecs-xwd)Vulnerability Type: Heap-Based…
continue reading..
