Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control
Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...
Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk
runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS...
Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation
Apache ActiveMQ users should urgently patch three newly disclosed vulnerabilities — CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877 — that can crash brokers, break temporary-destination isolation, and let low-privilege Web Console...
25-Year-Old cURL Vulnerability Patched in Record-Breaking Security Release Fixing 18 CVEs
A critical authentication bypass flaw in cURL that had existed undetected for over 25 years has been patched in curl 8.21.0, released June 24, 2026. The release simultaneously...
Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users
A critical heap overread vulnerability in Squid Proxy, dubbed Squidbleed, has gone undetected since 1997. Discovered with the help of AI, the flaw allows an attacker controlling an...
SAP June 2026 Patch Day: Four Critical Flaws Including CVSS 9.9 SAML Bypass in NetWeaver ABAP
SAP's June 2026 Security Patch Day addressed 15 security notes including four critical vulnerabilities. The most severe — CVE-2026-44748 (CVSS 9.9) — is an XML Signature Wrapping flaw...
Google Chrome 149 Patches 429 Vulnerabilities Including 22 Critical — Update Immediately
Google has released Chrome 149.0.7827.53 with 429 security fixes, including 22 rated critical. The patch covers use-after-free and memory corruption bugs across ANGLE, GPU, Network, Password Manager, and...
GitLab Patches High-Severity Duo AI Identity Flaw and Multiple Authorization, DoS Vulnerabilities
GitLab has released emergency security patches (versions 19.0.1, 18.11.4, 18.10.7) fixing a CVSS 8.2 Duo AI identity flaw (CVE-2026-4868) that could enable lateral movement, alongside a Wiki denial-of-service...