Index
Search
Search the public record. Drafts and scheduled notes are not included.
news
Apache Struts 7.4.0 fixes four security flaws
On 5 October 2026 Apache published S2-075 through S2-078 for Struts, covering OGNL injection in the legacy RESTful mapper, BigDecimal response expansion, an unbounded REST body read, and a shared date/time message formatter. Fixes ship in 7.4.0 and 6.12.0. No CVSS scores or CISA KEV listings yet.
Published 53m ago
news
Visual Composer LFI is CVE-2026-12227
Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.
Published 2h ago
threats
The Gitea diffpatch bug is listed by CISA
CVE-2026-60004 lets a user with repository write access run commands as the Gitea service account. Fixed in 1.27.1 on 27 July 2026. CISA listed it on 25 August 2026. NVD scores it 9.8 and does not mention the write-access requirement.
Published 2h ago
threats
NetScaler command execution is CVE-2026-88771
Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.
Published 2h ago
news
The PostgreSQL fuzzystrmatch bug needs a database login
CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.
Published 2h ago
research
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 2h ago
research
Three Authlib signature bugs are not one patch
CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.
Published 2h ago
research
Two MongoDB driver bugs are not confirmed code execution
CVE-2026-96748 lets an untrusted hostname add a server to a PyMongo client. CVE-2026-96746 can crash the C driver. Both are scored 8.3. Neither NVD text is arbitrary code execution, and neither is in the CISA catalog.
Published 2h ago