Zimbra SNMP Flaw CVE-2026-73570 Actively Exploited for Unauthenticated RCE
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-60004 with a CVSS score of 9.8, has been patched in Gitea, the…
Cybersecurity researchers have discovered over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the public…
F5 has patched a critical heap buffer overflow vulnerability in NGINX, tracked as CVE-2026-42533, which can crash worker processes and may allow…
Researchers at firmware security firm Binarly have discovered six new vulnerabilities in U-Boot, the widely used bootloader for devices ranging from home…
A critical unpatched vulnerability, dubbed XRING, has been disclosed in XQUIC, Alibaba's open-source QUIC and HTTP/3 library. Discovered by FoxIO researcher Sébastien…
A newly disclosed Linux kernel vulnerability, dubbed "Bad Epoll" and tracked as CVE-2026-46242, allows unprivileged local users to gain full root access…
A critical heap over-read vulnerability in the Squid web proxy, dubbed 'Squidbleed' (CVE-2026-47729), can leak cleartext HTTP requests—including credentials and session tokens—to…