Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > vulnerability
#vulnerability

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

30 July 2026  |  dark6  |  Vulnerability

A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...

>> read more

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution

20 July 2026  |  dark6  |  Vulnerability

A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...

>> read more

wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...

>> read more

HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it was...

>> read more

Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users

23 June 2026  |  dark6  |  Vulnerability

A critical heap overread vulnerability in Squid Proxy, dubbed Squidbleed, has gone undetected since 1997. Discovered with the help of AI, the flaw allows an attacker controlling an...

>> read more

Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in the Wild

17 June 2026  |  dark6  |  Vulnerability

Threat actors are actively exploiting three critical Fortinet FortiSandbox vulnerabilities — including CVE-2026-39813, which has no prior exploitation history. All flaws allow unauthenticated remote access via the JRPC...

>> read more