Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > cve
#cve

Apache HTTP Server 2.4.69 Fixes 20 Flaws Across CGI, WebDAV and Proxy Modules

2 October 2026  |  dark6  |  Vulnerability

Apache HTTP Server 2.4.69 addresses 20 vulnerabilities that can cause code execution, memory corruption, crashes, data exposure or authentication problems under particular configurations. Administrators should upgrade, but risk-based...

>> read more

ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical

26 September 2026  |  dark6  |  Vulnerability

ServiceNow has patched five vulnerabilities in its AI Platform, including a SQL injection flaw and a missing-authorization bug that together could let an unauthenticated attacker read, alter, or...

>> read more

How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum

19 September 2026  |  dark6  |  Vulnerability

Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...

>> read more

Chrome 153 Patches 42 Security Flaws, Including Three Critical Memory Bugs

16 September 2026  |  dark6  |  Vulnerability

Google’s Chrome 153 stable update closes 42 vulnerabilities, including three critical memory-safety issues in Internals, Workers and WebGL. Users and administrators should ensure the browser has restarted on...

>> read more

MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution

10 September 2026  |  dark6  |  Vulnerability

A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...

>> read more

Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths

29 August 2026  |  dark6  |  Vulnerability

ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...

>> read more

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

4 August 2026  |  dark6  |  Vulnerability

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...

>> read more

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

27 July 2026  |  dark6  |  Vulnerability

Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...

>> read more