A security update for MISP fixes two vulnerabilities, including one classed as high severity, and the case underscores how a shared threat-intelligence platform can become a trust-boundary problem as much as a software bug.
A critical flaw tied to ConfigServer Security & Firewall shows how an optional helper service inside a security tool can become the real point of failure.
Critical and high-severity flaws in GitLab’s self-managed editions show how one patch cycle can decide whether an attacker merely reads files or reaches into code, credentials, and build pipelines.
A cluster of newly patched MongoDB flaws, including five rated high severity, shows why security teams need exact inventory, not generic update advice.
Multiple remediated flaws, including four rated high severity, turn a routine VPN update into a reminder that the real attack surface often sits in authentication, negotiation, and session setup.
A pair of critical VPN bugs, tracked as CVE-2026-85102 and CVE-2026-85103, shows why gateway software remains one of the most sensitive places in a network to leave unpatched.
GitLab is urging users to patch servers immediately against CVE-2026-85706, a maximum-severity path traversal flaw that highlights how quickly a file-path mistake can become an operational risk.
A vulnerability tracked as CVE-2026-65638 puts the spotlight on a rarely used CSF feature, showing how defensive software can still become an entry point when old code is left in place.
Two RouterOS vulnerabilities have entered CISA’s KEV catalog, a signal that defenders should treat exposed edge devices as urgent remediation candidates, not ordinary patch tickets.
A print-management weakness and an AI-assisted attack workflow show how routine enterprise software can become a rapid entry point when exposed systems stay unpatched.
A major Android security bulletin fixes 180 vulnerabilities, including critical remote-code-execution bugs in System and serious kernel flaws that can matter long after the update lands.
Authentication and privilege bugs in a repository manager can matter less like a login issue and more like a software-trust incident.
A newly addressed vulnerability in Autodesk Fusion is a reminder that a design platform can become a security boundary, not just a productivity tool.
A security update for Hikvision’s centralized access-control platform highlights how a flaw in the management layer can matter more than a problem at the door.
A critical patch release for self-managed GitLab closes paths that could have exposed files, secrets, and server-side code execution.
Three high-severity flaws in identity plumbing matter because they sit between users, policy enforcement, and backend systems, where small bugs can have outsized security consequences.
Three high-severity bugs, including a critical stored XSS issue, show how weaknesses in identity plumbing can create outsized risk at the control plane.
Three JFrog Artifactory vulnerabilities, including an authentication-bypass path and a token escalation chain, have put self-hosted deployments in the crosshairs of active exploitation.
The print-management vendor has folded earlier emergency patches into regular maintenance releases, a sign that defenders should treat the upgrade as a priority rather than a routine refresh.
A chained exploit against self-hosted JFrog Artifactory instances shows how patch lag can turn a build-system hub into a high-value foothold for intruders.