CVE-2026-81707 — Critical vulnerability brief
CVSS 9.3openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge…
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity…
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Ravie LakshmananAug 27, 2026Hacking News / Cybersecurity…
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
CVE-2026-75604 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A critical heap buffer overflow in libheif (CVSS v4 9.5) exploited via crafted AVIF images leads to remote code execution in Next.js…
A heap buffer overflow in libheif's image scaling code (all versions through v1.23.1) allows remote code execution when processing crafted AVIF files.…
A vulnerability in Anthropic Claude Code (and other AI tools) allows a low-privileged attacker to drop configuration files in a trusted Windows…
A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious…
A vulnerability in NVIDIA NemoClaw (CVSS 8.1) allows an attacker to gain control of the local Ollama model server via a single…