Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution

10 September 2026  |  dark6  |  Vulnerability

Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...

>> read more

MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution

10 September 2026  |  dark6  |  Vulnerability

A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...

>> read more

Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days

9 September 2026  |  dark6  |  Vulnerability

Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...

>> read more

Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...

>> read more

Fortinet Firewalls Under Siege: New PivotC2 Malware Exploits Critical CAPWAP Flaw

9 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated buffer overflow in FortiOS's CAPWAP service is being actively exploited to plant a custom Node.js post-exploitation toolkit dubbed PivotC2. Researchers say at least 178 devices...

>> read more

Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack

9 September 2026  |  dark6  |  Vulnerability

Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...

>> read more

Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...

>> read more

Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch

8 September 2026  |  dark6  |  Vulnerability

Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...

>> read more