SAP's August update fixes a CVSS 10.0 hole letting unauthenticated attackers run code in Commerce Cloud.
A zero-click Zoom flaw lets any meeting participant take over another attendee's device through the annotation feature.
A researcher found the Connective browser extension used by two million Belgians could be abused to read card data, steal…
WordPress ships an emergency fix for a pre-auth XSS chain that ends in PHP code execution.
Federal agencies have days to patch an exploited Progress ADC bug that drew hundreds of attack attempts.
CVE-2026-60004 lets a repository writer plant a git hook and run commands as the Gitea service account.
Chinese AI agents from Kimi K3 autonomously found zero-day vulnerabilities in Redis and developed functional remote code execution exploits.
Attackers could achieve SYSTEM-level code execution on Bing servers by uploading crafted SVG files through two chained vulnerabilities.
Sign in to your account