Aggregator
CVE-2026-17574 | HDF Group HDF5 up to 2.1.1 null pointer dereference
Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely
vBulletin has patched CVE-2026-61511, a critical remote code execution flaw that could let unauthenticated attackers execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier as well as versions 6.1.6 and earlier. The flaw exists in the file /includes/vb5/template/runtime.php, specifically within the vB5_Template_Runtime::runMaths() method. This function processes values […]
The post Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely appeared first on Cyber Security News.
CVE-2026-17572 | HDF Group HDF5 up to 2.1.1 SOHM list-index deserialization num_messages buffer overflow
CVE-2026-51297 | SQLite 3.41 JSON Parsing src/json.c use after free
CVE-2026-17573 | HDF Group HDF5 up to 2.1.1 double free
CVE-2026-42792 | Erlang OTP prior 27.3.4.15/28.5.0.4/29.0.4 Port Mapper erts/epmd/src/epmd_srv.c do_accept exceptional condition
CVE-2025-50455 | Alex Tselegidis EasyAppointments up to 1.5.1 Query Builder /customers/search order_by sql injection
Coca-Cola confirms data theft in Fairlife ransomware attack
CVE-2026-65562 | WPDeveloper BetterDocs Plugin up to 4.6.2 on WordPress cross site scripting
EY Data Breach Claimed by ShinyHunters Hacker Group
The notorious ShinyHunters extortion gang has publicly claimed responsibility for the Ernst & Young (EY) data breach, alleging it stole employee credentials and sensitive files through a supply-chain compromise of a third-party IT support platform. The claim, posted on the group’s dark web leak site with a “final warning” deadline of July 31, 2026, threatens […]
The post EY Data Breach Claimed by ShinyHunters Hacker Group appeared first on Cyber Security News.