Aggregator
CVE-2025-38140 | Linux Kernel up to 6.15.2 dm_revalidate_zones nr_zones allocation of resources (EUVD-2025-19803 / Nessus ID 265934)
CVE-2025-38141 | Linux Kernel up to 6.12.33/6.15.2 dm_get_live_table use after free (EUVD-2025-19802 / Nessus ID 265934)
CVE-2025-38139 | Linux Kernel up to 6.15.2 lib/iov_iter.c netfs_retry_write_stream out-of-bounds (EUVD-2025-19804 / Nessus ID 265934)
CVE-2025-38138 | Linux Kernel up to 6.15.2 dmaengine udma_probe null pointer dereference (EUVD-2025-19805 / Nessus ID 247771)
CVE-2026-27456 | util-linux up to 2.41.3 /usr/bin/mount fork link following (GHSA-qq4x-vfq4-9h9g / Nessus ID 307050)
CVE-2026-39977 | flatpak -builder up to 1.4.7 g_file_resolve_relative_path path traversal (Nessus ID 307042)
CVE-2026-23660 | Microsoft Windows Admin Center in Azure Portal access control (Nessus ID 307058)
CVE-2026-32862 | NI LabVIEW up to 26.1.0 VI File Parser InitResourceMgr out-of-bounds write (Nessus ID 307060)
CVE-2026-32196 | Microsoft Admin Center 2.6.2.6/2.6.4 cross site scripting (Nessus ID 307059)
CVE-2026-32863 | NI LabVIEW up to 26.1.0 VI File Parser sentry_transaction_context_set_operation out-of-bounds (Nessus ID 307060)
CVE-2026-32864 | NI LabVIEW up to 26.1.0 VI File Parser aligned_free out-of-bounds (Nessus ID 307060)
CVE-2020-24588 | Microsoft Windows up to Server 2019 Wireless Networking risky encryption (Nessus ID 307077 / WID-SEC-2025-1858)
CVE-2026-40260 | py-pdf pypdf up to 6.9.x XMP Metadata xml entity expansion (GHSA-3crg-w4f6-42mx / Nessus ID 307345)
CVE-2026-40253 | openCryptoki up to 3.26.0 on Linux/AIX asn1.c length out-of-bounds (GHSA-c9cf-6vr4-wfxm / Nessus ID 307346)
Ваша телефонная книга останется при вас. Разбираемся в новых настройках приватности Android
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns
According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024, the presence of this decades-old protocol continues to pose an exposure risk […]
The post Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns appeared first on Cyber Security News.
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands
A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. The vulnerability was originally discovered in November 2025 and has now been made public following Fortinet’s […]
The post PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands appeared first on Cyber Security News.