Langflow Fixes Critical RCE Vulnerability
Langflow released version 1.10.1 to address CVE-2026-9198, a critical code injection vulnerability allowing unauthenticated RCE.
Langflow released version 1.10.1 to address CVE-2026-9198, a critical code injection vulnerability allowing unauthenticated RCE.
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
CVE-2026-25243 is a Redis RCE vulnerability patched in May 2026. It is part of the same vulnerability family as the July 2026…
RedisBloom is a Redis module that provides probabilistic data structures like Bloom filters and TDigest. It was involved in the out-of-bounds write…
On July 23, 2026, Redis shipped seven security releases after researchers published authenticated remote code execution (RCE) proof-of-concept (PoC) exploits for stock…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
A critical remote code execution vulnerability in Microsoft SharePoint Server, CVE-2026-50522 (CVSS 9.8), is being actively exploited in the wild following the…
A lightweight AI model fine-tuned to find, validate, and patch software vulnerabilities. In tests, it found 55 unique confirmed V8 issues and…
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
CVE-2022-22947 is a remote code execution vulnerability in Spring Cloud Gateway that occurs when the Actuator endpoint is enabled and exposed unsecured.