ZCyberNews
中文

Articles

460 articles

PublicCMS Payment Logic Flaw CVE-2026-8738 Allows UnauthorizedMEDIUM
Vulnerabilities

PublicCMS Payment Logic Flaw CVE-2026-8738 Allows Unauthorized

CVE-2026-8738 (CVSS 6.5) in Sanluan PublicCMS 5.202506.d lets remote attackers manipulate the trade payment flow via business logic errors in TradeOrderController.pay.

CVE-2026-8738
3 min read
AI Agents Automate Exploitation of Obscure VulnerabilitiesHIGH
Industry News

AI Agents Automate Exploitation of Obscure Vulnerabilities

AI agents now discover and exploit obscure vulnerabilities autonomously, while AI-generated code floods pipelines with flaws. Defenders must adapt to agent-scale threats.

3 min read
Avada Builder WordPress Plugin Flaws Expose Site CredentialsHIGH
Vulnerabilities

Avada Builder WordPress Plugin Flaws Expose Site Credentials

CVE-2026-4782 and CVE-2026-4798 in Avada Builder (1M+ installs) let attackers read wp-config.php and extract database hashes. Patch to version 3.15.3.

CVE-2026-4782CVE-2026-4798
3 min read
Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape RiskHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape Risk

CVE-2026-8573 (CVSS 8.3) and CVE-2026-8577 (CVSS 8.8) in Chrome 148 on Windows allow sandbox escape and RCE via crafted video or HTML pages. Update now.

CVE-2026-8577CVE-2026-8573
4 min read
Chrome 148.0.7778.168 Patches Two High-Severity OOB Read FlawsHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Two High-Severity OOB Read Flaws

Google Chrome 148.0.7778.168 fixes CVE-2026-8543 and CVE-2026-8541 — two high-severity out-of-bounds read vulnerabilities in FileSystem and UI components on Mac and all platforms.

CVE-2026-8543CVE-2026-8541
4 min read
Chrome 148 Patches AI Site Isolation Bypass, Android Payment FlawHIGH
Vulnerabilities

Chrome 148 Patches AI Site Isolation Bypass, Android Payment Flaw

CVE-2026-8568 (CVSS 3.1) lets attackers bypass Chrome Site Isolation via AI features after renderer compromise; CVE-2026-8566 (CVSS 4.3) targets Android Payments.

CVE-2026-8568CVE-2026-8566
3 min read
Chrome 148 Patches ANGLE Data Leak, Google Lens UAFHIGH
Vulnerabilities

Chrome 148 Patches ANGLE Data Leak, Google Lens UAF

Google fixed CVE-2026-8556 (ANGLE cross-origin leak) and CVE-2026-8550 (Google Lens use-after-free) in Chrome 148.0.7778.168 for Windows. Both flaws require a compromised renderer.

CVE-2026-8556CVE-2026-8550
4 min read
Fleet Patches API Rate-Limiting Bypass via IP SpoofingHIGH
Vulnerabilities

Fleet Patches API Rate-Limiting Bypass via IP Spoofing

CVE-2026-46356: Unauthenticated attackers can bypass Fleet's API rate limiting by spoofing True-Client-IP headers, enabling brute-force login attempts on exposed instances.

CVE-2026-46356
3 min read
libsixel NULL Pointer Dereference CVE-2026-44638 Gets Low CVSSLOW
Vulnerabilities

libsixel NULL Pointer Dereference CVE-2026-44638 Gets Low CVSS

CVE-2026-44638: libsixel 1.8.7-r1 and earlier has a NULL pointer dereference in sixeldecoderaw and sixel_decode due to a wrong NULL check after malloc. CVSS 2.5.

CVE-2026-44638
3 min read
MCP Registry OIDC Flaw CVE-2026-44428 Lets Attackers Hijack GitHubMEDIUM
Vulnerabilities

MCP Registry OIDC Flaw CVE-2026-44428 Lets Attackers Hijack GitHub

CVE-2026-44428 (CVSS 4.7) in the MCP Registry before 1.7.6 lets attackers reuse stolen GitHub OIDC tokens across registry instances, enabling unauthorized server publishing and...

CVE-2026-44428
4 min read
Medical Management System Flaw Lets Attackers Reset Any PasswordMEDIUM
Vulnerabilities

Medical Management System Flaw Lets Attackers Reset Any Password

CVE-2025-67437 (CVSS 6.5) in an unnamed Medical Management System allows unauthenticated password reset via insecure permissions. No patch released.

CVE-2025-67437
3 min read
Open WebUI Patches Three Flaws: XSS, SVG Injection, Auth BypassHIGH
Vulnerabilities

Open WebUI Patches Three Flaws: XSS, SVG Injection, Auth Bypass

Open WebUI fixes CVE-2026-45314 (SVG XSS), CVE-2026-45303 (iframe script injection), and CVE-2026-44567 (pending role auth bypass) — all in self-hosted AI platform.

CVE-2026-45314CVE-2026-45303CVE-2026-44567
5 min read
← PrevPage 5 of 39Next →