Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Tue 4 Aug

IBM Langflow unauthenticated code injection (CVE-2026-9198)

CISA lists CVE-2026-9198 as a Langflow code-injection issue that allows unauthenticated remote code execution on default deployments. Do not internet-expose unauthenticated AI workflow UIs. Apply vendor mitigations; this desk does not invent a patch build.

NVD

tech ai

Vulnerabilities

Tue 4 Aug

Apache Tomcat (CVE-2026-34486)

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability. Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Wed 29 Jul

Ruby on Rails Active Storage arbitrary file read and possible RCE (CVE-2026-66066)

The Rails project's GitHub advisory says an unauthenticated attacker can abuse Active Storage image variant processing with libvips to read arbitrary files accessible to the Rails process, including environment secrets; exposed signing or service credentials can enable remote code execution or lateral movement. The affected configuration uses libvips for Active Storage and accepts untrusted image uploads. SecurityWeek reported on 31 August that VulnCheck had observed exploitation. Upgrade Active Storage to 7.2.3.2, 8.0.5.1 or 8.1.3.1, use libvips 8.13 or later, and rotate secret_key_base plus every other secret readable by the application process. Rails branches without a fixed release should move to a supported branch or remove libvips until they can patch.

Rails/GitHub security advisory (29 Jul 2026)

vulnerabilities

Vulnerabilities

Mon 27 Jul

Arista VeloCloud Orchestrator (CVE-2026-16812)

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability. Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities network

Vulnerabilities

Mon 27 Jul

Fortinet FortiOS (CVE-2025-68686)

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability. Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities network

Vulnerabilities

Wed 22 Jul

Microsoft SharePoint (CVE-2026-50522)

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability . Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Wed 22 Jul

Check Point SmartConsole (CVE-2026-16232)

Check Point SmartConsole Improper Authentication Vulnerability. Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities network

Vulnerabilities

Tue 21 Jul

DD-WRT DD-WRT (CVE-2021-27137)

DD-WRT Stack-Based Buffer Overflow Vulnerability. DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Tue 21 Jul

Langflow Langflow (CVE-2026-0770)

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability. Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

tech ai

Vulnerabilities

Tue 21 Jul

WordPress Core (CVE-2026-63030)

WordPress Core Interpretation Conflict Vulnerability. WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Tue 21 Jul

WordPress Core (CVE-2026-60137)

WordPress Core SQL Injection Vulnerability. WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities

Vulnerabilities

Thu 16 Jul

Microsoft SharePoint (CVE-2026-58644)

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Apply vendor mitigations. Check the NVD record and the vendor advisory for affected versions and the patch.

NVD

vulnerabilities