Vulnerabilities
125 articles RSS
Redis Patches ACL Transaction Bypass and Unauthenticated Cluster Bus Across Five Release Branches
Redis 8.10.2, 8.8.3, 8.6.7, 8.4.7 and 8.2.10 ship security fixes; four close an ACL key-check gap at EXEC, and all add an opt-in refusal for unauthenticated cluster buses.
GitLab Patches Critical Self-Hosted AI Gateway Flaw CVE-2026-90970, a CVSS 9.9 Prompt-Template Sandbox Escape
GitLab fixed CVE-2026-90970, a CVSS 9.9 flaw that let authenticated Duo Agent Platform users escape a prompt template sandbox on self-hosted AI Gateways.
OpenSSL Patches 14 Vulnerabilities in 4.0.3 and Backports, Led by a High-Severity DTLS Heap Disclosure Flaw
OpenSSL's 29 September 2026 advisory covers 14 CVEs, one High-severity DTLS flaw that can leak heap memory, one Moderate and 12 Low; fixes ship in 4.0.3, 3.6.5, 3.5.9 and 3.4.8.
Next.js 16.3.8 and 15.5.27 Patch Seven Vulnerabilities, Including a High-Severity Image Optimizer SSRF, While Two Others Slip
Vercel's Next.js team released 16.3.8 and 15.5.27 fixing one high, five medium and one low severity flaw; a critical and a high fix were postponed over upstream delays.
Official MCP Python SDK OAuth Flaw Lets Malicious Servers Steal Client Secrets, Fixed in 1.30.0 and 2.2.0
A high-severity flaw in the official MCP Python SDK let a malicious server redirect OAuth credentials to an attacker's endpoint; fixes ship in 1.30.0 and 2.2.0, with extra steps needed.
Citrix Confirms Exploitation of Two Critical NetScaler RCE Flaws, CVE-2026-88771 and CVE-2026-88772, as CISA Adds Both to KEV Catalog
Citrix confirmed exploitation of two critical NetScaler ADC and Gateway flaws, both CVSS v4 9.5, and shipped fixes; CISA added both to its KEV catalog as of September 27, 2026.
Vercel Patches Critical Next.js ImageResponse RCE Traced to a Satori SVG-Escaping Flaw
Vercel shipped Next.js 16.3.6 to fix a critical, 9.5-rated remote code execution flaw in ImageResponse rooted in a Satori SVG-escaping bug, CVE-2026-94545.
Critical Bifrost AI Gateway Flaw Let Attackers Run Commands Without Credentials
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Plugin4Shell Flaw Lets Repository Owners Swap Pinned Plugin Code in Claude Code, Codex, and Copilot
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
Rust Security Team Fixes Miri Bug That Let GitHub Actions Caches Leak Secrets to Pull Requests
The Rust Security Response Team disclosed and patched a Miri flaw that stored all environment variables in target/, letting cached CI output expose secrets to pull requests.
GitHub Security Lab Finds Same-Second Race Condition in JupyterLab CI Action That Enables Code Execution
A TOCTOU race in JupyterLab's update-snapshots-checkout GitHub Action let a same-second commit push bypass its authorization check and reach attacker-controlled code execution, GitHub Security Lab found.
GitSpawn Flaws Let Malicious .git Configs Run Attacker Code in Claude Code, Cursor, Codex, and Other AI Coding Agents
Manifold Security found eight flaws across seven AI coding agents that let a repository's git config silently execute code the moment it is opened.