F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.
News
-
-
The new SharePoint zero-day vulnerability follows a pattern that patching alone won’t fix: a chained attack that steals server keys before the update ever lands.
-
A step-by-step guide to Zoom’s critical Windows account takeover vulnerability: which products are affected, whether it’s being exploited, and what to patch first.
-
Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.
-
A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.
-
A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.
-
Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …
-
An exposed criminal server reveals exactly which plugin flaws powered a mass WordPress webshell attack. Use this checklist to check your own sites now.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.