isolated-vm Sandbox Library Patches Critical Escape Flaw
isolated-vm, a popular open-source Node.js library for running untrusted JavaScript in V8 isolates, patched a critical vulnerability (GHSA-864f-rcv7-6rh4) in versions 6.2.0 and…
isolated-vm, a popular open-source Node.js library for running untrusted JavaScript in V8 isolates, patched a critical vulnerability (GHSA-864f-rcv7-6rh4) in versions 6.2.0 and…
Semtech is a semiconductor company that confirmed the findings and plans to ship patches written by Qualcomm for affected components.
Apache Tomcat released versions 11.0.21, 10.1.54, and 9.0.117 to fix CVE-2026-34486, a missing encryption vulnerability.
Langflow released version 1.10.1 to address CVE-2026-9198, a critical code injection vulnerability allowing unauthenticated RCE.
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, has been patched in Gitea, the…
Gitea, a popular open-source Git hosting platform, released version 1.27.1 to address CVE-2026-60004, a critical remote code execution vulnerability. The flaw could…
JetBrains has disclosed a critical vulnerability in on-premise versions of TeamCity, tracked as CVE-2026-63077 with a CVSS score of 9.8. The flaw…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
Zimbra 10.1.20 is the latest version that patches nine security vulnerabilities including critical SNMP command injection and multiple XSS flaws.
A critical vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allows attackers to log in as any user by exploiting…