WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.
Splunk has disclosed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating ...
Progress disclosed a critical command injection flaw that lets malicious OpenAPI or Swagger documents execute OS commands.
Nozomi reports that Cling botnet uses STUN traffic to conceal command-and-control activity and attacks against vulnerable IoT ...
SonicWall fixed four SMA1000 flaws, including a 10.0-rated SSRF reachable before authentication; it says none are known to be ...
Exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra, started shortly after patches rolled out.
AWS has released fixes for four security vulnerabilities affecting its open-source Loom AI agent orchestration platform and ...
NVIDIA patched 14 vulnerabilities in Infrastructure Controller for Linux that enable code execution, data tampering, information disclosure.
CVE-2026-102255 could allow remote unauthenticated attackers to direct a SMA 1000 appliance to issue requests on their behalf ...
Microsoft warns that attackers are actively exploiting CVE-2026-73570 to run commands, steal Zimbra authentication data, and ...
SonicWall has issued security updates to address four vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances.