» Tag
cve
31 postsAuthenticated RCE Exploits Hit Redis via Stream, TDigest, TopK Bugs
Authenticated RCE chain hits Redis 6.2.22 through 8.8.1 via stream NACK double-free, TDigest and TopK module bugs, bypassing two prior CVE patches.
RefluXFS: XFS reflink race lets Linux users escalate to root (CVE-2026-64600)
Qualys details RefluXFS (CVE-2026-64600), an XFS reflink race enabling local privilege escalation to root on default RHEL, Rocky, and Fedora Server installs.
Pre-Auth SQL Injection in WordPress Core via Batch API Desync
Array desync in WordPress's REST batch API enables pre-auth SQL injection (CVE-2026-63030/60137); details plus a fast bitmask extraction technique.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comMCP Security Needs Four Layers, Not Just a Gateway
Why MCP security requires four separate control layers beyond the gateway, backed by real CVEs and practical production controls.
RubyGems CDN Caching Bug Could Leak Legacy API Keys to Other Users
A RubyGems.org CDN caching flaw could leak legacy API keys between users for up to an hour; CVSS 7.2, all legacy keys have been revoked.
CosmosEscape: How a Bug Exposed Every Azure Cosmos DB Account
A Gremlin API sandbox escape in Azure Cosmos DB exposed a master key capable of compromising any database on the service, Wiz Research found.
FFmpeg's 16-Year-Old MagicYUV Flaw Enables RCE via Crafted Video
A 16-year-old heap overflow in FFmpeg's MagicYUV decoder (CVE-2026-8461) enables RCE via crafted AVI files, hitting Jellyfin, Nextcloud and more.
Microsoft's AI Bug Hunt Tripled CVEs: The Data Behind It
Microsoft's July 2026 patch hit 1150 CVEs, 3x the prior baseline. Public CVRF data reveals how AI-driven bug hunting also reshaped severity.
Operation CameraSwarm: 14,000+ Dahua Cameras Compromised
Hunt.io traced Operation CameraSwarm to an exposed dev directory, revealing three exploit paths behind 14,000+ compromised Dahua cameras.
GeoServer jsonArrayContains SQLi Confirmed Regression of CVE-2023-25158
GeoServer's GHSA-mqjf-5f49-2fjh SQL injection is a confirmed regression of CVE-2023-25158, enabling unauthenticated RCE. Patch and mitigation details inside.