VulnerabilitiesLangflow Under Attack: RCE Flaw Exposes OpenAI and AWS Keys, Root Credentials
Langflow CVE-2026-0768 RCE flaw exploited to steal AWS and OpenAI keys with root access. See affected versions, fix in 1.11.6 and detection tips.
VulnerabilitiesLangflow CVE-2026-0768 RCE flaw exploited to steal AWS and OpenAI keys with root access. See affected versions, fix in 1.11.6 and detection tips.
VulnerabilitiesChaotic Eclipse released PrettyPrague, a PoC exploiting Avast Sandbox zero-day to access Windows SAM database and gain SYSTEM privileges. No patch yet.
VulnerabilitiesJFrog Artifactory CVE-2026-82329 (CVSS 9.8) allows unauthenticated admin token creation. Patch self-hosted instances to prevent supply chain compromise.
VulnerabilitiesCronos resumed after Tectonic exploit inflated TONIC 100x for $74M loans. Only $6M ETH stolen per PeckShield; network halted, rolled back, TVL collapsed.
VulnerabilitiesCVE-2026-66066 exploited in the wild: crafted image uploads abuse Rails Active Storage and libvips to read arbitrary files and steal secrets.
VulnerabilitiesHardBreacher is a PoC privilege escalation exploit targeting Kaspersky Endpoint Security's UI process. Kaspersky says a fix is available via update.
VulnerabilitiesPaperCut releases emergency patches for two exploited zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, allowing authentication bypass and arbitrary code execution.
VulnerabilitiesActive exploitation of two PaperCut vulnerabilities allows pre-authentication RCE in MF and NG products. Patch immediately to secure systems.
VulnerabilitiesCVE-2026-65643 is a critical flaw in cPanel/WHM allowing privilege escalation to root. Immediate updates are required to prevent server compromise.