CVE-2026-41703: VMware ESX Out-of-Bounds Read Information Disclosure
An out-of-bounds read vulnerability in VMware ESX with a CVSS score of 7.6. An attacker with VM deployment privileges can trigger information…
An out-of-bounds read vulnerability in VMware ESX with a CVSS score of 7.6. An attacker with VM deployment privileges can trigger information…
A new attack technique called Bit2Watt, detailed by researchers from Zhejiang University in a paper accepted to CHES 2026, demonstrates how a…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
Okta's Red Team has disclosed a denial-of-service vulnerability in OpenSSL, dubbed HollowByte, that allows an attacker to freeze server memory using 11-byte…
A moderate-severity vulnerability in OpenSSL's QUIC implementation allows unbounded memory growth via the PATH_CHALLENGE handler, leading to denial of service through memory…
SAP has released its July 2026 security updates, addressing multiple vulnerabilities including a critical out-of-bounds write flaw in SAP NetWeaver Application Server…
Researchers at firmware security firm Binarly have discovered six new vulnerabilities in U-Boot, the widely used bootloader for devices ranging from home…
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…
OpenSSL versions prior to 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 are vulnerable to HollowByte, a denial-of-service attack that freezes server memory via…
BeyondTrust has released security updates to address multiple critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) products. The…