oss-security·1d agoCVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs#apache#apache-roller#cve-2026-82375CVE-2026-82375 17 sources
SecurityWeek·3d ago highAdobe Patches Critical Flaws in Connect, AEM Forms#adobe#connect#aem-forms 2 min
SecurityWeek·9d ago highCheck Point, Kaspersky, Tanium Patch Product Vulnerabilities#check-point#kaspersky#patching 2 min
GBHackers·10d ago highJenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft#cicd#credential-exposure#groovy 4 min
oss-security·10d agoCVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability#apache#cve-2026-68536#javaCVE-2026-68536 2 sources
ZDI Published Advisories·11d agoZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability#0day#airbyte#data-connectorCVE-2026-92203 11 sources
Cyber Security News·12d ago highAWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions#aws#ec2#iam 3 min1
Security Affairs·16d ago criticalUK Council Attack Linked to Mass Exploitation of SonicWall Flaw#active-directory#credential-theft#cve-2026-15409 in the wild 6 min2
The Hacker News·17d agoNearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key#ai-gateway#cloud-security#kev in the wild 7 min
GBHackers·17d ago highCritical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root#arangodb#authentication-bypass#patch 5 min1
oss-security·18d agoCVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF#apache#credential-theft#impalaCVE-2026-57866 3 sources1
oss-security·18d agoCVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery#apache#avro#impalaCVE-2026-540481
CERT/CC Vulnerability Notes·18d agoVU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability#ascensio#cert-cc#file-collaborationCVE-2026-84282 3 min
Full Disclosure·23d agoNext.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists#dns-rebinding#nextjs#ssrfVulnerability
Full Disclosure·23d agoFlextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery#cms#flextype#phpVulnerability 8 sources
CyberScoop·23d ago criticalAttackers exploit zero-days in consistently besieged SonicWall product#cisa#command-injection#kev in the wild 4 min
Qualys ThreatPROTECT·23d ago criticalCISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)#cisa#kev#rceCVE-2026-83548 in the wild 2 min
Rapid7 Blog·24d ago criticalCritical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild#cisa#command-injection#kev in the wild 3 min
The Register · Security·24d ago criticalSonicWall's SMA1000 boxes under active attack again#command-injection#kev#sma1000 in the wild 2 min
Security Affairs·24d ago criticalSonicWall Patches Two New Actively Exploited Zero#active-exploitation#command-injection#sma-1000 in the wild 2 min1
The Hacker News·24d ago criticalAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain#command-injection#exploitation#sma-1000 in the wild 2 min
Infosecurity Magazine·25d ago highHackers Chain Two New SonicWall Zero-Day Vulnerabilities#edge-device#rce#sma1000 in the wild 2 min
Help Net Security·25d ago highSonicWall SMA 1000 appliances under attack via zero-day flaws#actively-exploited#command-injection#sma-1000 in the wild 2 min