#open-source
8 articles
Between 12 April and 4 August 2026, ZCyberNews published 15 articles on open-source security, covering four critical, two high, three medium, and five informational findings. The coverage highlighted CVE-2026-25874 (CVSS 9.3), CVE-2026-33626 (CVSS 7.5), CVE-2026-8114 (CVSS 6.5), and CVE-2026-42286. Affected sectors included technology, research, software development, enterprise applications, and financial services, with a global reach. These reports documented vulnerabilities and advisories relevant to organisations relying on open-source components, offering details on severity and potential impact across the observed period.
CRITICALFrontier AI Finds 14,090 Zero-Days in OSS in 2 Months
Unit 42's NOVA system uncovered 14,090 novel vulnerabilities across 3,915 OSS projects in two months — 40% high or critical severity — collapsing the patch window to near zero.
HIGHEmlog CSRF Flaw CVE-2026-42286 Lets Attackers Hijack Admin Actions
CVE-2026-42286: Missing CSRF protection in Emlog prior to 2.6.11 lets attackers trick authenticated admins into unauthorized plugin management and config changes.
MEDIUMJeecgBoot SQLi Flaw CVE-2026-8114 Exploit Publicly Available
CVE-2026-8114 (CVSS 6.5) in JeecgBoot up to 3.9.1 enables remote SQL injection via the /sys/dict/loadTreeData endpoint. Exploit code is public.
CRITICALPyTorch Lightning Compromised in PyPI Supply Chain Attack
Threat actors pushed malicious PyTorch Lightning versions 2.6.2 and 2.6.3 to PyPI on April 30, 2026, stealing credentials via a typosquatted dependency — Aikido Security, Socket,…
CRITICALCVE-2026-25874: Unpatched RCE Flaw in Hugging Face LeRobot
CVE-2026-25874 (CVSS 9.3) in Hugging Face LeRobot enables unauthenticated RCE via unsafe deserialization.
HIGHLMDeploy SSRF Flaw CVE-2026-33626 Exploited 13 Hours After Disclosure
CVE-2026-33626 (CVSS 7.5) in LMDeploy, an open-source LLM toolkit, was exploited in the wild within 13 hours of public disclosure, enabling SSRF attacks to access sensitive…
INFORMATIONALLegitify Open-Source Tool Scans GitHub, GitLab for Security Misconfigurations
Legit Security releases Legitify, an open-source scanner that identifies security misconfigurations in GitHub and GitLab organizations, repositories, and CI/CD runners to combat software supply chain risks.
MEDIUMOberon System 3 Native Port for Raspberry Pi Raises Supply Chain Security Concerns
A native port of the Oberon System 3 for Raspberry Pi 3, distributed via a pre-configured SD card image, presents a potential supply chain attack vector. The image's provenance and integrity cannot be fully verified, highlighting risks in third-party firmware distribution.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.