Skip to main content Skip to local navigation
Home » Category: 'Vulnerabilities'

Vulnerabilities

Apple CoreGraphics Code Execution Vulnerability (CVE-2026-86950)

A recently disclosed vulnerability (CVE-2026-86950) affects Apple iOS, iPadOS, and macOS and may allow an attacker to execute arbitrary code by convincing a user to process a specially crafted file. Severity level:CVSS Score: 8.8/High Description: CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's CoreGraphics framework. Processing a maliciously crafted file may trigger memory corruption and […]

Citrix NetScaler ADC/Gateway RCE Vulnerabilities (CVE-2026-88771 & CVE-2026-88772)

A recently disclosed set of vulnerabilities (CVE-2026-88771 and CVE-2026-88772) affects Citrix NetScaler ADC and Citrix NetScaler Gateway and may allow unauthenticated remote attackers to execute arbitrary code on vulnerable appliances. Severity level:CVSS Score: 9.5/Critical. Description: CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway. The flaw could allow an unauthenticated […]

WordPress RCE (CVE-2026-87902)

A recently disclosed vulnerability (CVE-2026-87902) affects WordPress Core and may allow an unauthenticated remote attacker to achieve remote code execution (RCE) on vulnerable WordPress sites when specific theme and server conditions are present. Severity level:CVSS Score: 9.2/Critical. Description: CVE-2026-87902 is a critical path traversal vulnerability in WordPress Core's get_page_template() functionality. The flaw allows an unauthenticated […]

Linux Kernel Container Escape Vulnerability (CVE-2026-80521)

A recently disclosed vulnerability (CVE-2026-80521) affects the Linux kernel AF_UNIX socket subsystem and may allow an attacker to escape a container and obtain root privileges on the host system. Severity level:CVSS Score: 7.8/High Description: CVE-2026-80521 is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket subsystem caused by a race condition in the garbage collection […]

GitLab Path Traversal Vulnerability (CVE-2026-85706)

A recently disclosed vulnerability (CVE-2026-85706) affects GitLab Community Edition (CE) and Enterprise Edition (EE) and may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, and other sensitive information. Severity level:CVSS Score: 10/Critical. Description: CVE-2026-85706 is a critical path traversal vulnerability in GitLab's Repository Commits API. The […]

macOS Screen Sharing Authentication Bypass (CVE-2026-65400)

A recently disclosed vulnerability (CVE-2026-65400) affects Apple macOS Screen Sharing and may allow a remote attacker on the network to authenticate without valid credentials, potentially gaining unauthorized access to affected systems. Severity level:CVSS Score: 9.8/Critical. Description: CVE-2026-65400 is a critical authentication bypass vulnerability in the macOS Screen Sharing component. Due to improper state management during […]

WPMU DEV Dashboard Auth Bypass (CVE-2026-15459)

A recently disclosed vulnerability (CVE-2026-15459) affects the WPMU DEV Dashboard plugin for WordPress and may allow an unauthenticated remote attacker to bypass authentication and perform privileged administrative actions. Severity level:CVSS Score: 8.1/High. Description: CVE-2026-15459 is an authentication bypass vulnerability in the WPMU DEV Dashboard plugin for WordPress. An unauthenticated attacker can exploit the flaw on […]

VMware vCenter Server multiple vulnerabilities (CVE-2026-59309,CVE-2026-59310)

A recently disclosed set of vulnerabilities (CVE-2026-59309 and CVE-2026-59310) affects VMware vCenter Server and may allow a remote attacker with network access to bypass authentication and execute arbitrary code on vulnerable systems. Severity level:CVSS Score: 9.8/Critical. Description: CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service component of VMware vCenter Server. A […]

WordPress RCE Vulnerability (CVE-2026-63030)

A recently discovered vulnerability (CVE-2026-63030) that affects WordPress Core and allow an unauthenticated remote attacker to achieve remote code execution (RCE). Severity level:CVSS Score: 9.8/Critical. Description: WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. CVE-2026-63030 is a critical REST […]

Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412)

A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access. Severity level:CVSS Score: 9.8/Critical. Description: CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and […]

Linux kernel vulnerability (CVE-2026-43503)

A recently disclosed vulnerability (CVE-2026-43503), also known as DirtyClone, affects the Linux kernel and may allow a local unprivileged user to gain root privileges on vulnerable systems. Severity level:CVSS Score: 8.8/High. Description: CVE-2026-43503 (DirtyClone) is a high-severity Linux kernel privilege escalation vulnerability caused by improper handling of shared memory fragments in the networking subsystem. A […]

Oracle PeopleSoft Remote Code Execution Vulnerability (CVE-2026-35273)

A recently disclosed vulnerability (CVE‑2026‑35273) affects Oracle PeopleSoft Enterprise PeopleTools and may allow a remote, unauthenticated attacker to execute arbitrary code and take full control of affected systems. Severity level:CVSS Score: 9.8/Critical. Description: CVE‑2026‑35273 is a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. The flaw allows an unauthenticated attacker with […]

Windows Netlogon RCE Vulnerability (CVE-2026-41089)

A recently discovered critical vulnerability (CVE‑2026‑41089) affects Microsoft Windows Server and may allow a remote, unauthenticated attacker to execute arbitrary code on affected systems by targeting the Netlogon service. Severity level:CVSS Score: 9.8/Critical. Description: CVE‑2026‑41089 is a stack‑based buffer overflow vulnerability in the Windows Netlogon service. The flaw occurs due to improper handling of specially […]

7-Zip Heap Buffer Overflow (CVE-2026-48095)

A recently disclosed vulnerability (CVE‑2026‑48095) affects 7-Zip and may allow a remote attacker to execute arbitrary code on vulnerable systems by tricking the users into opening a specially crafted archive file.Severity level:CVSS Score: 8.8/High.Description:CVE‑2026‑48095 is a heap buffer overflow in 7‑Zip’s NTFS handler caused by improper memory allocation when processing crafted archive data. Opening a […]

Linux Kernel Local root Privilege Escalation (CVE-2026-46333)

A recently discovered vulnerability (CVE‑2026‑46333) affects the Linux kernel and may allow a local, unprivileged attacker to access sensitive files and escalate privileges to root, potentially leading to full system compromise.Severity level:CVSS Score: 7.1/High.Description:CVE‑2026‑46333 is a race condition vulnerability in the Linux kernel’s _ptrace_may_access() function caused by improper handling of process state during termination. When […]