Aggregator
CVE-2026-4496 | sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880 src/gitUtils.ts child_process.exec os command injection (EUVD-2026-13768)
CVE-2026-4497 | Totolink WA300 5.2cu.7112_B20190227 /cgi-bin/cstecgi.cgi recvUpgradeNewFw os command injection (EUVD-2026-13770)
CVE-2026-4437 | GNU C Library up to 2.43 nsswitch.conf gethostbyaddr_r out-of-bounds (EUVD-2026-13796)
CVE-2025-63261 | AWStats 8.0 open command injection (EUVD-2025-208911)
CVE-2026-4438 | GNU C Library up to 2.43 nsswitch.conf gethostbyaddr/gethostbyaddr_r input validation (EUVD-2026-13798)
CVE-2026-2378 | BrowserCompany of New York ArcSearch up to 1.12.6 on Android Web ui layer (EUVD-2026-13808)
CVE-2026-3584 | wpchill Kali Forms Plugin up to 2.4.9 on WordPress Placeholder form_process code injection (EUVD-2026-13814)
Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution
Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel update rolls out versions 146.0.7680.153 and 146.0.7680.154 for Windows and macOS, while Linux users will receive version 146.0.7680.153. This critical patch cycle is designed to […]
The post Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution appeared first on Cyber Security News.
苹果解释M5芯片为什么分成三种核心 因为每种核心的工作场景都不同
Texas Gov. Orders State Review of Chinese-Made Medtech
Texas Gov. Abbott has ordered agencies to review foreign-made connected medical devices - especially those from Chinese manufacturers - used in state-owned facilities for cybersecurity issues that could pose security and privacy risks to patients and healthcare infrastructure.
ISMG Editors: Stryker Attack Hits Healthcare Supply Chain
In this week's panel, four ISMG editors unpacked the cyber dimensions of the Stryker attack amid the escalating Iran-Israel-U.S. tensions, the growing controversy around CISA leadership and alleged protocol breaches, and a new set of concerns related to AI agents bypassing security controls.
FBI Seizes Iranian Online Leak Sites After Stryker Hack
U.S. federal agents seized four web domains associated with Iranian hacking operations days after a threat actor going by Handala posted screenshots it said came from inside the IT systems of medical device manufacturer Stryker. The registrars used to create them are located in the United States.
Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager
Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score of 9.8, placing it among the most severe classifications in Oracle’s risk framework. CVE-2026-21992 is an […]
The post Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager appeared first on Cyber Security News.