Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

1 August 2026  |  dark6  |  Vulnerability

A broken access control bug (CVE-2026-17059) in Keycloak's Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue...

>> read more

Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk

1 August 2026  |  dark6  |  Vulnerability

JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. Administrators are...

>> read more

Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns

31 July 2026  |  dark6  |  Vulnerability

CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...

>> read more

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

30 July 2026  |  dark6  |  Vulnerability

A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...

>> read more

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

27 July 2026  |  dark6  |  Vulnerability

Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...

>> read more

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

27 July 2026  |  dark6  |  Vulnerability

A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...

>> read more

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

27 July 2026  |  dark6  |  Vulnerability

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....

>> read more

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more