CVE-2026-20245: how a tenant-list CSV upload turned Cisco SD-WAN Manager into a root shell
Inside CVE-2026-20245: an unvalidated file-path argument to a privileged tenant-list upload script lets a netadmin execute commands as root...
25 posts tagged with "CVE".
All postsInside CVE-2026-20245: an unvalidated file-path argument to a privileged tenant-list upload script lets a netadmin execute commands as root...
Inside CVE-2026-45659: an insecure-deserialization (CWE-502) flaw lets any authenticated SharePoint Server Site Member run code on-prem (CVS...
Inside CVE-2026-48095: an undefined-behavior shift in 7-Zip's NTFS handler allocates a 1-byte buffer, then writes 256 MB into it, corrupting...
Inside CVE-2026-43640: the C# short-circuit boolean that lets any authenticated Bitwarden admin with a stolen session pull or rotate the org...
Ivanti Ivanti Endpoint Manager Mobile (versions up to 12.8.0.0) contains an improper input validation vulnerability that allows remote code...
Inside CVE-2026-42945 (NGINX Rift): the 18-year-old heap buffer overflow in NGINX's ngx_http_rewrite_module that enables unauthenticated RCE...
Breakdown of CVE-2026-45321, the TanStack supply chain compromise. An attacker chained a pull_request_target misconfiguration, GitHub Action...
A critical double-free bug in Apache HTTP Server 2.4.66 lets unauthenticated attackers crash worker processes with two HTTP/2 frames, and es...
Dirty Frag chains two Linux kernel LPE vulnerabilities (CVE-2026-43284 in IPSec ESP, CVE-2026-43500 in RxRPC) to achieve instant root on vir...
A regression in ASP.NET Core Data Protection broke HMAC validation, exposing apps to forged authentication cookies and padding oracle attack...
CVE-2026-41940 is a critical (CVSS 9.8) authentication bypass in cPanel and WHM that lets unauthenticated attackers gain root-level server a...
A logic flaw in the Linux kernel's crypto subsystem, dormant since 2017, now lets any unprivileged local user write into the page cache of f...
Connect your repositories and let AI agents handle continuous scanning, research, and triage.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.