Two SharePoint Flaws Chain Into Unauthenticated Server Code Execution
Rapid7 joined a SharePoint identity bypass to unsafe .NET type creation. August's cumulative updates complete Microsoft's two-cycle fix.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
Rapid7 joined a SharePoint identity bypass to unsafe .NET type creation. August's cumulative updates complete Microsoft's two-cycle fix.
Read article →An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
Read article →WordPress 7.0.3 fixes a pre-auth login-page XSS that can turn administrator interaction with a malicious site into PHP execution.
Read article →CISA confirms exploitation of a TeamCity flaw that lets an unauthenticated network attacker run commands as the server process, putting secrets and build integrity at risk.
Read article →Langflow, N-central, and Tomcat flaws entered CISA's exploited catalog. One gives unauthenticated callers Python execution by default.
Read article →A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.
Read article →CVE-2026-41613 let crafted MCP install links persist settings that the VS Code preview did not show. Version 1.119.1 fixes the boundary.
Read article →A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Read article →Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Read article →Chrome fixed more security bugs in two milestones than in the previous 23 while using AI across discovery, triage and fix preparation.
Read article →An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
Read article →A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
Read article →A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.
Read article →