#vulnerability


GitLab warns of critical RCE vulnerability in AI Gateway service

Oct 2, 2026 // 23:17

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. AI Gateway is […]

Kiteworks patches max severity code injection vulnerability

Oct 1, 2026 // 16:56

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. […]

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Sep 16, 2026 // 14:10

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the […]

SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

Sep 8, 2026 // 17:56

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. […]

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

Aug 28, 2026 // 18:57

Author: Gene Moody, Field CTO at Action1 AI can help us find vulnerabilities faster than ever. But what happens when the rest of the vulnerability […]

Frontier AI: Vulnerability Management’s Systemic Revolution

Aug 25, 2026 // 14:19

Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams […]

CISA warns of hackers exploiting critical MLflow vulnerability

Aug 20, 2026 // 14:16

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability. MLflow is an open-source AI […]

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Aug 12, 2026 // 12:15

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability […]

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Jul 20, 2026 // 12:18

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in […]

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

Jul 20, 2026 // 00:22

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with […]

1 2 3 … 8 Next