CVE-2026-20896: Gitea Reverse-Proxy Authentication Bypass
A critical reverse-proxy authentication bypass in Gitea Docker images, patched in June 2026. Threat actors were observed probing the flaw 13 days…
A critical reverse-proxy authentication bypass in Gitea Docker images, patched in June 2026. Threat actors were observed probing the flaw 13 days…
Security firm Sysdig has identified what it believes is the first ransomware attack fully orchestrated by an AI agent, dubbed JADEPUFFER. The…
Check Point VPN is a virtual private network solution, associated with CVE-2026-50751 used as a lure in the ChocoPoC campaign.
A vulnerability in Argo CD where the Redis cache lacked authentication, allowing any pod in the cluster to poison deployment data. Fixed…
An unknown threat actor is exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two new malware families:…
A critical security flaw in Oracle E-Business Suite, tracked as CVE-2026-46817 (CVSS 9.8), is now actively exploited in the wild. The vulnerability,…
CVE-2022-40684 is an authentication bypass vulnerability in Fortinet FortiOS. It was exploited in the StrikeShark campaign.
Microsoft SharePoint is the affected product in CVE-2026-55040, a critical authentication bypass vulnerability. The flaw allows unauthenticated attackers to forge JWT tokens…
Ivanti, Fortinet, and SAP have released security patches addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.Fortinet…
An authentication bypass vulnerability in Ivanti Sentry before versions R10.5.2, R10.6.2, and R10.7.1 allows remote unauthenticated attackers to create arbitrary administrative accounts…