Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw

23 July 2026  |  dark6  |  Vulnerability

ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentication. Security...

>> read more

RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root

23 July 2026  |  dark6  |  Vulnerability

Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...

>> read more

Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity

22 July 2026  |  dark6  |  Vulnerability

Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...

>> read more

Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw

22 July 2026  |  dark6  |  Vulnerability

A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...

>> read more

New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File

21 July 2026  |  dark6  |  Vulnerability

Bitdefender researchers have detailed how Windows 'bind links' — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to...

>> read more

Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution

20 July 2026  |  dark6  |  Vulnerability

A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...

>> read more

wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...

>> read more