Critical OpenWrt DHCPv6 Flaw CVE-2026-53921 Allows Unauthenticated Remote Code Execution as Root
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including…
A maximum-severity command injection vulnerability in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. Tracked as CVE-2026-16812 with a…
A command-injection flaw in the Linksys E1700 router disclosed in August 2025 with a public exploit. The vendor did not respond to…
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
A critical command injection vulnerability in ImageMagick's delegate mechanism allows remote code execution via crafted image files. This 2016 vulnerability is the…
An open-source image processing suite used by Bing's pipeline. Its delegate mechanism was exploited to achieve command injection. The article recommends disabling…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…