A recent critical flaw in Oracle E-Business Suite has crossed from disclosure into active exploitation, putting payment workflows in the crosshairs of opportunistic attackers.
Fresh critical and high-severity NGINX fixes show how a few rewrite and proxy directives can turn an internet-facing layer into a crash point, and in narrower conditions, a path toward code execution.
An unauthenticated flaw in Langflow can let attackers write files and reach remote code execution, turning a workflow tool into a high-risk internet target when exposed.
A critical flaw tracked as CVE-2026-9739 affects Google’s MCP Toolbox for Databases and may let unauthenticated attackers abuse SSE-based deployments through DNS rebinding.