Skip to content
THREATWIRE

Desk

Security news

Reporting from the desk. A story is published when it is edited, not when a feed delivers it.

High

Security news

The PostgreSQL fuzzystrmatch bug needs a database login

CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.

Published 2m ago

Critical

Security news

OpenOffice Java bug has no released fix

CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.

Published 1h ago

Critical

Security news

The Gotenberg public PoC is not a confirmed RCE

CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.

Published 1h ago

Security news

Opening the public record

ThreatWire is live as a record, not a firehose. X carries the short dispatch. The site carries the detail, and only after it is edited.

Published 6h ago