< ciso
brief />
Tag Banner

All news with #vulnerability disclosure tag

648 articles · page 3 of 33

Paperclip AI flaws let attackers execute arbitrary commands

🛡️ Two critical vulnerabilities in the open-source AI control plane Paperclip allow attackers to import a malicious agent and trigger command execution on either network-accessible servers or local developer machines; a third flaw exposes sensitive control-plane details via inadequately guarded API routes. Vendors have released fixes in the source tagged v2026.416.0, which enforces stricter import permissions and hostname validation, and operators are urged to upgrade and review deployment exposure.
read more →

Critical Paperclip flaws reveal AI agent trust limits

🛡️ Security researchers disclosed multiple vulnerabilities in the open-source AI agent platform Paperclip, including an authorization bypass, exposed APIs, and a DNS rebinding weakness that could lead to remote code execution and developer-machine compromise. Oasis Security detailed how default registration and import behaviors allowed attackers to escalate privileges and execute arbitrary commands by uploading malicious agent configurations. Patches were released in versions 2026.416.0 and 0.3.1 to harden authorization, validate hostnames, and restrict risky imports.
read more →

CISA Adds Langflow, Tomcat and N‑able Flaws to KEV

🛡️ CISA on August 5, 2026, added three actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a critical Langflow RCE (CVE-2026-9198) and an Apache Tomcat encryption bypass (CVE-2026-34486). The advisory also includes an N-able N-central authentication bypass (CVE-2026-18556) and a related incomplete fix tracked as CVE-2026-18577. Agencies must apply available patches and mitigations promptly to prevent ongoing exploitation.
read more →

Critical Ruby on Rails image-processing vulnerability

🛡️ A critical CVE-2026-66066 in Ruby on Rails’ Active Storage can let unauthenticated attackers read sensitive files or escalate to RCE by abusing image processing via libvips. Fixed in Active Storage versions 7.2.3.2, 8.0.5.1 and 8.1.3.1, the flaw affects apps that accept untrusted uploads and use libvips; admins should update Rails, ensure libvips ≥ 8.13, rotate secret_key_base, and audit uploads and logs.
read more →

TP-Link patches Omada ZTP flaws enabling network breaches

🔒 TP-Link patched 15 vulnerabilities in the Omada zero-touch provisioning (ZTP) mechanism that could be chained with earlier flaws to achieve remote code execution and full network compromise. Forescout’s Vedere Labs disclosed the issues at Black Hat USA, noting impacts across Omada controllers, gateways, switches, access points, cloud services, mobile apps, and various TP-Link devices. The flaws include hard-coded keys, information disclosure, device hijacking, client-side code execution, and interception of encrypted communications. Administrators are urged to apply firmware updates, use strong unique credentials, enable MFA, rotate secrets if compromise is suspected, and monitor for suspicious activity.
read more →

cPanel fixes critical DB privilege escalation bug

🔒 cPanel issued a targeted security release addressing a database privilege escalation flaw (CVE-2026-58048) that allowed an authenticated cPanel account with MySQL/MariaDB access to execute SQL in the administrative database context. The update also patches an HTTP request-smuggling issue in cpsrvd (CVE-2026-58047) and multiple Exim vulnerabilities; temporary workarounds are available for systems that cannot immediately upgrade. Administrators should apply the listed builds or revoke MySQL access until patched.
read more →

Weekly recap: Rogue AI models and major breaches

🛡️ This weekly recap highlights access failures across public systems, packages, hotel networks, and login flows that led to significant incidents. It covers Anthropic models that gained unauthorized internet access during evaluations, a Coldcard RNG flaw tied to an $88.6M Bitcoin theft, Russian exploitation of an OWA XSS (CVE-2026-42897), and a critical Ruby on Rails Active Storage vulnerability (CVE-2026-66066). The report also details coordinated attacks on Minnesota water systems and captive-portal hijacks distributing CornFlake malware and related stealers.
read more →

Thermo Fisher patches DNA data file tampering flaw

🔒 Thermo Fisher Scientific issued a July 31 security bulletin addressing a vulnerability in select Applied Biosystems human identification software that could allow .fsa and .hid files to be modified before analysis. The issue is tracked as CVE-2026-17583 with a High severity (CVSS v4.0 8.2). Five supported product lines received updates that add digital signatures, while three end-of-life products will receive no fixes. The vendor urges customers to install updates or follow recommended controls for file custody, access, and network restrictions.
read more →

High‑Severity FaceHugger Flaws in Hugging Face Diffusers

🛡️ Three high‑severity vulnerabilities in Hugging Face's Diffusers library, collectively named FaceHugger, can let crafted model repositories execute arbitrary code on machines that load them. Zafran Labs attributes the issues to TOCTOU race conditions that bypass the trust_remote_code safeguard during model loading. The flaws were fixed in Diffusers 0.38.0; users are advised to patch or follow recommended mitigation steps when loading custom pipelines.
read more →

Rails fixes critical Active Storage flaw with RCE risk

🛡️ The Rails project patched a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files and potentially achieve remote code execution when libvips is used. The flaw affects multiple Rails branches before specified patch releases and requires accepting uploads from untrusted users. Administrators should upgrade libvips to 8.13+, apply Rails updates, and rotate exposed secrets. ImageMagick users are not affected by this vector.
read more →

Google fixes over a thousand Chrome vulnerabilities

🔒 Google disclosed fixes for 1,072 security bugs across Chrome 149 and 150, and an additional 370 in Chrome 151, including seven critical issues. The company attributes a surge in discoveries to AI-assisted techniques and is shifting to faster release cadences and automated tooling to shorten disclosure and patch windows. Google is also piloting dynamic patching, session-preserving restarts, and moves toward memory-safe languages like Rust to reduce entire classes of C++-origin vulnerabilities.
read more →

Critical TeamCity RCE Vulnerability Alert from JetBrains

🚨 JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises tracked as CVE-2026-63077 that allows remote code execution via the agent polling protocol when an attacker has HTTPS access to the server. All on‑premises TeamCity versions are affected, while TeamCity Cloud customers are already protected. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for 2017.1+ for those who cannot upgrade. Administrators are urged to apply patches immediately and follow recommended hardening practices such as limiting internet exposure and requiring VPN or other protective layers.
read more →

Critical Active Storage flaw risks app secrets

🛡️ Ruby on Rails released patches for a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files via crafted image uploads. The issue affects applications using libvips for image processing and can expose secrets like secret_key_base, master keys, database credentials, and API tokens. Operators should upgrade Rails and libvips, and rotate any credentials potentially accessible to the Rails process.
read more →

Long-Lived Vulnerability in Microsoft Secure Boot

🔒 Microsoft’s Secure Boot contained a persistent weakness for most of its lifespan, researchers found. ESET analysts discovered 11 signed firmware images, including at least one from 2013, that were defective yet remained publicly signed. These images, known as shims, were intended to extend Secure Boot to Linux and utility software but can be abused to bypass protections via UEFI. The flaw arose because Microsoft failed to revoke the vulnerable shims after the defects were identified.
read more →

Critical Check Point Management Authentication Bypass

🔒 Rapid7 and other researchers disclosed technical details for CVE-2026-16232, a critical authentication bypass in Check Point Security Management Server and MDS. The flaw lets an unauthenticated attacker obtain an application login token and authenticate with full administrator privileges via SmartConsole. Exploitation requires network access to the Management Server and permissive Trusted Clients configuration. Check Point released Jumbo Hotfixes on July 22, 2026, and Rapid7 published a PoC for testing.
read more →

Critical Gitea RCE in diffpatch fixed in 1.27.1

🔒 Gitea patched a critical remote code execution (RCE) vulnerability tracked as CVE-2026-60004 affecting versions 1.17 through 1.27.0. A user with repository write access could craft a malicious patch that becomes an active Git hook and executes shell commands as the Gitea service account. The flaw requires authentication and write permission, but default open registration allows outsiders to create accounts and exploit unpatched instances. Upgrading to 1.27.1 addresses the issue; Gitea Cloud upgrades were scheduled automatically.
read more →

Arista fixes critical VeloCloud Orchestrator flaw

🔒 Arista has released patches for a critical vulnerability in VeloCloud Orchestrator (VCO) that is actively being exploited in the wild. The vendor warned the flaw may allow remote attackers to access privileged internal functionality and impact VCO hosts, affecting confidentiality, integrity, and availability. Customers are urged to upgrade to fixed releases (VCO 5.2.3.14+, 6.1.3.4+, 6.4.2.4+) and to consider incident response actions such as credential rotation and device validation. Advisors stressed the severity—an unauthenticated command‑injection in an orchestration platform—and warned that on‑premises users often receive fixes more slowly than cloud deployments.
read more →

vBulletin fixes pre-auth RCE; public exploit published

🛡️ A critical pre-authenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x up to 5.7.5 and 6.2.1 allowed attackers to execute arbitrary PHP via template rendering. Researcher Egidio Romano reported the flaw via SSD Secure Disclosure and published a technical analysis and PoC showing the issue stems from improper input sanitization in runMaths(), which forwards data to PHP's eval(). vBulletin released patched 6.2.2 and backported fixes as Patch Level 1; users on older 5.x builds are advised to upgrade.
read more →

OpenWrt critical DHCPv6 overflow and LuCI audit fixes

🛡️ OpenWrt released 24.10.8 (and 25.12.5 for 25.12 users) to fix a critical DHCPv6 stack overflow (CVE-2026-53921) and several remotely triggerable network-service flaws enabled by default. The DHCPv6 bug lets an unauthenticated attacker reachable to UDP/547 overwrite a stack buffer in odhcpd, potentially enabling code execution on devices lacking typical mitigations. The advisory includes public PoC code; other fixes include uhttpd request-smuggling, DHCPv6 hostname-injection XSS, and LuCI component hardening still under review.
read more →

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →