Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > vulnerability
#vulnerability

How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum

19 September 2026  |  dark6  |  Vulnerability

Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...

>> read more

Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass

8 September 2026  |  dark6  |  Vulnerability

The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...

>> read more

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

27 August 2026  |  dark6  |  Vulnerability

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...

>> read more

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more

18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...

>> read more

Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN

6 August 2026  |  dark6  |  Vulnerability

Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation...

>> read more

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login

4 August 2026  |  dark6  |  Vulnerability

SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...

>> read more

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

4 August 2026  |  dark6  |  Vulnerability

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...

>> read more