Topic: memory corruption

  • Linux bug: Single errant character causes high-severity flaw

    Linux bug: Single errant character causes high-severity flaw

    A high-severity Linux vulnerability (CVE-2026-23111) in the nf_tables kernel subsystem allows unprivileged users to escalate privileges to root-level control. The flaw is a use-after-free bug caused by a single misplaced exclamation point in the code, enabling attackers to plant malicious code in...

    Read More »
  • Critical NGINX Bug: DoS & Potential RCE in 18-Year-Old Flaw

    Critical NGINX Bug: DoS & Potential RCE in 18-Year-Old Flaw

    A critical heap buffer overflow vulnerability (CVE-2026-42945, CVSS 9.2) was discovered in NGINX's rewrite module, present for nearly two decades in versions 0.6.27 through 1.30.0, enabling denial of service and potential remote code execution when specific rewrite and set directives are combined...

    Read More »
  • Urgent Redis Update Fixes Critical RCE Vulnerability

    Urgent Redis Update Fixes Critical RCE Vulnerability

    A critical use-after-free vulnerability (CVE-2025-49844) in Redis's Lua scripting allows authenticated attackers to execute arbitrary code on the host server, affecting versions 8.2.1 and earlier. The flaw is exacerbated by default configurations in Redis container images that disable authenticat...

    Read More »
  • SAP Warns of Critical Flaws in NetWeaver and Commerce Cloud

    SAP Warns of Critical Flaws in NetWeaver and Commerce Cloud

    SAP's July 2026 security updates patch 16 vulnerabilities, with three critical flaws affecting NetWeaver, Commerce Cloud, and AppRouter. The critical flaws include a memory corruption issue in NetWeaver AS ABAP (CVE-2026-44747), HTTP Request Smuggling in AppRouter (CVE-2026-27690), and default cr...

    Read More »
  • Apple's Critical Security Update: Install Now

    Apple's Critical Security Update: Install Now

    Apple has released an urgent security patch (CVE-2026-20700) for a zero-day vulnerability that is being actively exploited across its major device lines. The flaw, a memory corruption issue, allows attackers to execute arbitrary code for purposes like spyware installation or silent device takeove...

    Read More »
  • Apple Patches Critical Zero-Day Flaw Actively Exploited in Attacks

    Apple Patches Critical Zero-Day Flaw Actively Exploited in Attacks

    Apple has patched a critical zero-day vulnerability (CVE-2026-20700) in its dyld component, which was exploited in a sophisticated, targeted attack against older iOS versions. The updates also fix two related WebKit vulnerabilities, all discovered and reported by Google's Threat Analysis Group, t...

    Read More »
  • 32-Year-Old Bug in GNU Telnetd Enables Pre-Auth RCE (CVE-2026-32746)

    32-Year-Old Bug in GNU Telnetd Enables Pre-Auth RCE (CVE-2026-32746)

    A critical 32-year-old buffer overflow vulnerability (CVE-2026-32746) in the GNU Telnet daemon allows remote code execution before authentication, affecting countless systems due to widespread code integration. Exploitation is highly complex and system-specific, constrained by protocol limitation...

    Read More »
  • Urgent Microsoft Update: Patch Windows 10, 11, Server Now

    Urgent Microsoft Update: Patch Windows 10, 11, Server Now

    Microsoft has urgently patched a zero-day vulnerability (CVE-2025-62215) in the Windows Kernel, which is already being actively exploited to gain system-level privileges. The flaw involves improper synchronization in concurrent execution, allowing attackers to escalate privileges after initial ac...

    Read More »
  • Patch MongoDB Now: Critical Security Alert

    Patch MongoDB Now: Critical Security Alert

    A critical, high-severity vulnerability (CVE-2025-14847) in MongoDB allows unauthenticated attackers to remotely read uninitialized heap memory due to a flaw in the server's zlib compression implementation. The vulnerability impacts a wide range of MongoDB versions, from 3.6 through 8.2.2, and th...

    Read More »
  • Apple Patches Critical Zero-Day Flaw in "Extremely Sophisticated Attack"

    Apple Patches Critical Zero-Day Flaw in "Extremely Sophisticated Attack"

    Apple has released a critical security update to address a zero-day vulnerability (CVE-2025-43300) that was exploited in a sophisticated attack against specific individuals, allowing arbitrary code execution via malicious image files. The vulnerability, caused by improper bounds checking in the I...

    Read More »
  • Critical DrayTek Router Flaw Allows Remote Code Execution

    Critical DrayTek Router Flaw Allows Remote Code Execution

    A critical vulnerability (CVE-2025-10547) in DrayTek routers allows unauthenticated remote attackers to execute commands via crafted HTTP/HTTPS requests, potentially leading to system crashes or code execution. DrayTek has released firmware updates for 35 router models and advises immediate insta...

    Read More »
  • Urgent Apple Update Fixes Critical Security Exploits

    Urgent Apple Update Fixes Critical Security Exploits

    Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine, which is used across iPhones, iPads, and Macs. The flaws, discovered through a collaboration between Apple and Google, could allow memor...

    Read More »