ZCyberNews
中文

Articles

460 articles

Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited inHIGH
Vulnerabilities

Microsoft Warns of Exchange Zero-Day CVE-2026-42897 Exploited in

CVE-2026-42897 is a high-severity Exchange Server spoofing flaw exploited in the wild, enabling XSS-based code execution via Outlook on the web.

CVE-2026-42897
4 min read
Next.js Patches Two Authorization Bypass Flaws in App RouterHIGH
Vulnerabilities

Next.js Patches Two Authorization Bypass Flaws in App Router

CVE-2026-44574 (CVSS 8.1) and CVE-2026-44575 (CVSS 7.5) let attackers bypass middleware-based auth checks in Next.js App Router via crafted .rsc URLs and query parameter...

CVE-2026-44574CVE-2026-44575
3 min read
Next.js Patches XSS and DoS Flaws in Cache ComponentsHIGH
Vulnerabilities

Next.js Patches XSS and DoS Flaws in Cache Components

CVE-2026-44580 (CVSS 6.1) enables XSS via beforeInteractive scripts; CVE-2026-44579 (CVSS 7.5) triggers connection exhaustion in Partial Prerendering.

CVE-2026-44580CVE-2026-44579
3 min read
OpenImageIO Integer Overflow CVE-2026-43908 Enables OOB WriteHIGH
Vulnerabilities

OpenImageIO Integer Overflow CVE-2026-43908 Enables OOB Write

CVE-2026-43908 (CVSS 8.8): A signed 32-bit integer overflow in OpenImageIO's ConvertCbYCrYToRGB() causes out-of-bounds writes, risking crashes or code execution in VFX pipelines.

CVE-2026-43908
3 min read
OpenImageIO TGA Decoder Flaw CVE-2026-43996 Enables OOB ReadMEDIUM
Vulnerabilities

OpenImageIO TGA Decoder Flaw CVE-2026-43996 Enables OOB Read

CVE-2026-43996 (CVSS 5.5) in OpenImageIO TGA decoder uses unsigned 32-bit wrap to bypass bounds check, enabling out-of-bounds read. Affects versions prior to 3.0.18.0 and 3.1.13.0.

CVE-2026-43996
3 min read
Palo Alto GlobalProtect Flaws Let Attackers Intercept EncryptedHIGH
Vulnerabilities

Palo Alto GlobalProtect Flaws Let Attackers Intercept Encrypted

CVE-2026-0249: Multiple improper certificate validation flaws in Palo Alto Networks GlobalProtect app let local or same-subnet attackers intercept encrypted traffic and install...

CVE-2026-0249
3 min read
protobufjs Flaw CVE-2026-45740 Enables DoS via Deeply Nested JSONHIGH
Vulnerabilities

protobufjs Flaw CVE-2026-45740 Enables DoS via Deeply Nested JSON

CVE-2026-45740 (CVSS 7.5) in protobufjs lets attackers crash Node.js apps by sending crafted JSON descriptors with deeply nested namespaces — affects versions before 7.5.8 and...

CVE-2026-45740
3 min read
AI Hallucinations Exploit Human Trust in Critical InfrastructureHIGH
Industry News

AI Hallucinations Exploit Human Trust in Critical Infrastructure

AI models produce confident but incorrect outputs that have led to misconfigured firewalls and pipeline valve errors, researchers warn.

3 min read
AI Security Startup Funding Surpasses Acquisitions by $1B in 1Q26INFORMATIONAL
Industry News

AI Security Startup Funding Surpasses Acquisitions by $1B in 1Q26

Dark Reading reports AI security startup investments exceeded acquisition value by over $1 billion in 1Q26, signaling a widening 'valley of death' for maturing firms.

2 min read
Cisco Catalyst SD-WAN Controller Flaw CVE-2026-20182 Scores PerfectCRITICAL
Vulnerabilities

Cisco Catalyst SD-WAN Controller Flaw CVE-2026-20182 Scores Perfect

Rapid7 discovered CVE-2026-20182, a 10.0-CVSS authentication bypass in Cisco Catalyst SD-WAN Controller. Unauthenticated attackers can inject SSH keys and issue NETCONF commands.

CVE-2026-20182CVE-2026-20127
4 min read
F5 Patches 51 Flaws: NGINX DoS, BIG-IP RCE Among Critical FixesCRITICAL
Vulnerabilities

F5 Patches 51 Flaws: NGINX DoS, BIG-IP RCE Among Critical Fixes

F5 fixed 19 high-severity and 32 medium-severity bugs across BIG-IP, BIG-IQ, and NGINX. The most severe, CVE-2026-42945 (CVSS 9.2), enables heap overflow DoS in NGINX rewrite...

CVE-2026-42945CVE-2026-41225CVE-2026-41957+2
4 min read
Hackers Exploit PraisonAI Auth Bypass Hours After DisclosureHIGH
Vulnerabilities

Hackers Exploit PraisonAI Auth Bypass Hours After Disclosure

Sysdig detected CVE-2026-44338 exploitation attempts within 3 hours 44 minutes of public advisory — attackers probed /agents on exposed PraisonAI instances.

CVE-2026-44338
3 min read
← PrevPage 7 of 39Next →