A weekly security roundup points to a familiar pattern: attackers are leaning on trusted software, AI tools, and browser behavior to turn routine actions into execution paths.
The HEIF Heist disclosure is a reminder that a photo upload can become a server-side parsing problem, especially when systems automatically decode HEIF, HEIC, or AVIF files.
A crafted preview link can blur the line between browsing themes and running server-side code, turning an authenticated admin session into a dangerous attack path.
A hard-coded key flaw in Access Rights Manager pushed a high-severity update into the spotlight, with potential unauthenticated remote code execution on the table for older deployments.
A critical pre-authentication code-execution flaw in Orkes Conductor shows how orchestration platforms can become high-value attack surfaces when script evaluation sits too close to the server core.
A critical unauthenticated RCE in Orkes Conductor shows how a workflow engine can become dangerous when runtime-defined JSON is allowed to cross the line into executable code.
A high-severity flaw in SolarWinds Access Rights Manager is a reminder that the most sensitive software in a network is often the software that manages trust itself.
Multiple fixed flaws in Grafana, including three rated high severity, show why dashboards and observability stacks need the same patch discipline as core infrastructure.
A critical PHP object injection flaw in Tutor LMS shows how a single plugin bug can move from authenticated access to remote code and lasting footholds.
A critical heap overflow in Unbound’s DNSSEC validator shows how a trust-checking path can become the most dangerous code in the resolver.
A security update aimed at the control plane matters because a bug in the login path can put the systems that govern policy and visibility at risk.
A critical overflow in Check Point’s management and log stack turns an ordinary authentication path into a potentially root-level remote attack surface.
A batch of critical HPE EdgeConnect flaws highlights a familiar but dangerous pattern: when the management plane is weak, the whole network can inherit the risk.
A pair of unauthenticated remote-code-execution flaws in The Events Calendar shows how ordinary plugin features can become high-risk attack surfaces when rendering and widget logic are exposed to untrusted input.
A critical flaw in a WooCommerce wholesale plugin shows how a routine business feature can turn into an unauthenticated path to file upload, web shells, and remote code execution.
A Marimo remote code execution case shows how quickly a web-facing notebook can turn into a bridge toward internal infrastructure once a shell is in play.
CISA has warned that attackers are still exploiting a critical VMware vCenter remote code execution flaw patched in July, with ransomware groups now joining the activity.
A widely used events plugin for WordPress was patched after critical unauthenticated flaws surfaced, showing how a single validation bug can create a broad remote-code-execution risk.
A reported Gitea flaw tied to CVE-2026-60004 shows how a routine diff-application feature can cross the line from collaboration tool to host compromise, with source theft and Linux malware in the frame.
A flaw in a self-hosted Git platform can turn ordinary repository activity into remote code execution, making code servers a prime target for attackers hunting industrial and government environments.