Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > vulnerability
#vulnerability

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

27 August 2026  |  dark6  |  Vulnerability

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...

>> read more

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more

18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...

>> read more

Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN

6 August 2026  |  dark6  |  Vulnerability

Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation...

>> read more

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login

4 August 2026  |  dark6  |  Vulnerability

SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...

>> read more

Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw

4 August 2026  |  dark6  |  Vulnerability

A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...

>> read more

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

30 July 2026  |  dark6  |  Vulnerability

A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...

>> read more

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more