Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads
A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...
AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software
A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...
Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs
Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...
Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution
A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...
HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death
A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it was...
Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users
A critical heap overread vulnerability in Squid Proxy, dubbed Squidbleed, has gone undetected since 1997. Discovered with the help of AI, the flaw allows an attacker controlling an...
Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in the Wild
Threat actors are actively exploiting three critical Fortinet FortiSandbox vulnerabilities — including CVE-2026-39813, which has no prior exploitation history. All flaws allow unauthenticated remote access via the JRPC...