Aggregator
CVE-2026-32863 | NI LabVIEW up to 26.1.0 VI File Parser sentry_transaction_context_set_operation out-of-bounds (Nessus ID 307060)
CVE-2026-32864 | NI LabVIEW up to 26.1.0 VI File Parser aligned_free out-of-bounds (Nessus ID 307060)
CVE-2020-24588 | Microsoft Windows up to Server 2019 Wireless Networking risky encryption (Nessus ID 307077 / WID-SEC-2025-1858)
CVE-2026-40260 | py-pdf pypdf up to 6.9.x XMP Metadata xml entity expansion (GHSA-3crg-w4f6-42mx / Nessus ID 307345)
CVE-2026-40253 | openCryptoki up to 3.26.0 on Linux/AIX asn1.c length out-of-bounds (GHSA-c9cf-6vr4-wfxm / Nessus ID 307346)
Ваша телефонная книга останется при вас. Разбираемся в новых настройках приватности Android
遏制域入侵:预测性屏蔽如何阻断横向移动
AI Agent供应链投毒:一个恶意Skill如何窃取你的全部凭据
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns
According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024, the presence of this decades-old protocol continues to pose an exposure risk […]
The post Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns appeared first on Cyber Security News.
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands
A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. The vulnerability was originally discovered in November 2025 and has now been made public following Fortinet’s […]
The post PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands appeared first on Cyber Security News.