Apache Patches a Dozen Tomcat Flaws Spanning WebSockets, HTTP/2, and TLS Checks
Apache has released Tomcat 11.0.26 to close twelve security holes across WebSocket, HTTP/2, AJP, authentication, and certificate-validation code, including a message-smuggling bug and a header mix-up introduced by...
GitLab’s Email-to-Issue Feature Can Be Hijacked to Commit Code as Any User
Researchers at Aikido Security found that GitLab’s incoming-email work-item feature relies on a long-lived, non-expiring token that, if exposed, lets an attacker submit merge requests and land commits...
Maximum-Severity Flaw in D-Link Routers Lets Attackers Take Over Devices With No Login Required
A stack-based buffer overflow in D-Link's DIR-822A router, rated a perfect CVSS 10.0, can be triggered remotely with no authentication and no user interaction, and a working public...
How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum
Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...
Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass
The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...
Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs
Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...
Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution
A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...
18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers
A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...