Multiple high-severity flaws in a widely used media engine highlight how a single crafted file can stress the systems that ingest, transcode, and stream user content.
Four high-severity flaws in a widely used SSH library show how a routine outbound connection can turn into a memory-corruption event before an operator notices anything unusual.
A critical command-injection flaw in Arista VeloCloud Orchestrator shows why the software that steers networks can be as sensitive as the networks themselves.
A new round of fixes in the ubiquitous multimedia framework shows how one malformed file can still turn a routine decode job into a serious security problem.
A Fastjson flaw reported as active in attacks shows how a routine JSON library can become an unauthenticated entry point when risky defaults stay in place.
CVE-2026-16812 puts an on-premises SD-WAN management plane under pressure, where a single command injection bug could become a wide operational problem.
iOS 26.6 and iPadOS 26.6 close multiple security holes across the kernel, WebKit, and privileged system services, making this a patch cycle defenders should treat as urgent.
Arista’s fix for an actively exploited command injection flaw in on-premises VeloCloud Orchestrator deployments is a reminder that management interfaces can be the most dangerous part of the network.
JetBrains has flagged a severe TeamCity On-Premises flaw that can let a remote attacker run code without logging in, putting build servers and pipeline trust under immediate pressure.
An actively exploited Fastjson zero-day is a reminder that a convenience library can become a code-execution risk when attacker-controlled data reaches the wrong parser path.
Public exploit details for vBulletin show how a simple unauthenticated request can cross into PHP execution, putting unpatched forum servers in the crosshairs.
A patched expression-sandbox escape in n8n shows how an authenticated editor account can become far more dangerous than it looks when the boundary between workflow logic and server code fails.
The open-source SSH client library sits inside downstream software, so a flaw in its handshake, crypto, or SFTP logic can turn a routine connection into a crash or memory-corruption event.
A critical RCE warning around Fastjson 1.2.83 shows how a library once treated as the safer choice can still become dangerous when JSON parsing meets a Spring Boot fat-jar deployment.
A newly tracked vulnerability in vBulletin can let unauthenticated attackers run arbitrary PHP code on affected servers without user interaction or credentials.
A new three-day cooldown in Dependabot changes automated updates from instant reaction to release-age vetting, aiming to blunt fast-moving supply chain abuse.
A new default cooldown for Dependabot version updates is designed to slow the automatic adoption of newly released packages and narrow the window for supply-chain abuse.
CVE-2026-61511 places self-hosted vBulletin forums in a high-risk category because the reported flaw can be reached before authentication and may let an attacker run PHP code on the server.
A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.
A local flaw in WalletService appears to turn ordinary authenticated access into SYSTEM-level control, showing how service boundaries can fail in the most dangerous way.