Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope.
This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API...
SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication.
CVE-2026-28323 affects SolarWinds Web Help Desk deployments using SAML 2.0 single sign-on (SSO)and was fixed in version 2026.2.1,...
CISA has issued a warning regarding a serious vulnerability in the Cisco Secure Firewall Management Center (FMC), which is currently being exploited in attacks.
The flaw, identified as CVE-2026-20316, affects Cisco's centralized management platform for firewall solutions and could allow...
Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This vulnerability, tracked as CVE-2026-20316, arises from static credentials embedded in the FMC web interface.
Although the flaw carries a CVSS...
Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions.
The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service...
A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization.
This issue, uncovered by researchers at the University of California,...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action.
Tracked as CVE-2026-16232,...
ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices.
The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386,...
A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files.
Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple...
Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows.
Tracked as CVE-2026-58443, the vulnerability affects Gitea versions...