Apple’s Private Cloud Compute Flaw CVE-2026-20685
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to…
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to…
Security researchers have demonstrated a new attack technique that abuses Windows Plug and Play (PnP) auto-install to achieve full SYSTEM privileges on…
Cisco has released security updates to address 12 vulnerabilities affecting Catalyst SD-WAN and IOS XE Software, including three with a CVSS score…
CVE-2026-20273 is a high-severity vulnerability in Cisco IOS XE Software with a CVSS score of 8.6. It is caused by improper input…
CVE-2026-48374 is a high-severity vulnerability in Adobe Bridge with a CVSS score of 7.8. It is a path traversal issue that could…
cgi-io is a CGI component in OpenWrt for file I/O operations. It is affected by CVE-2026-62947, a path traversal vulnerability that can…
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
CVE-2026-62947 is a path traversal vulnerability in OpenWrt's cgi-io component that can expose arbitrary root-readable files. It requires an authenticated session with…
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…