Monday, April 27, 2026
HomeVulnerabilities

Vulnerabilities

Chrome Update Fixes High-Severity Vulnerabilities Allowing Arbitrary Code Execution

Google has released a critical security update for Chrome, addressing six vulnerabilities that pose serious threats to user security. The update, Chrome version 139.0.7258.127/.128 for Windows and Mac, and 139.0.7258.127 for Linux, began rolling out on August 12, 2025, and will reach all users...

SAP Security Patch Day Fixes 15 Vulnerabilities, Including 3 Critical Injection Vulnerabilities

On August 12, 2025, SAP released its monthly Security Patch Day addressing 15 new vulnerabilities across multiple SAP products, marking one of the year's most significant security updates. The release includes three critical code injection vulnerabilities with maximum CVSS scores of 9.9, alongside four...

SSHamble: New Open-Source Tool Exposes SSH Protocol Vulnerabilities

SSHamble, a powerful open-source tool designed to identify and exploit vulnerabilities in SSH implementations, during his presentation at DEFCON 33 on August 9, 2025. The tool represents a significant advancement in SSH security testing, offering researchers and security professionals comprehensive capabilities to assess the...

Xerox FreeFlow Vulnerabilities Enable SSRF and Remote Code Execution Attacks

Xerox Corporation has released a critical security bulletin addressing two high-severity vulnerabilities in its FreeFlow Core v8.0.4 software that could allow attackers to execute server-side request forgery (SSRF) and remote code execution (RCE) attacks, potentially compromising enterprise printing infrastructure. Diagram illustrating the process of Remote...

Critical Security Vulnerabilities Discovered in WWBN AVideo, MedDream, and Eclipse ThreadX Module

Cisco Talos’ Vulnerability Discovery & Research team has disclosed a total of twelve security vulnerabilities affecting three distinct software products. Seven vulnerabilities impact WWBN AVideo, four reside within the MedDream PACS Premium system, and one exists in the Eclipse ThreadX FileX module. All issues...

CISA Issues 10 ICS Advisories on Critical Vulnerabilities and Exploitation Risks

The Cybersecurity and Infrastructure Security Agency (CISA) on August 7, 2025, published ten new Industrial Control Systems (ICS) advisories to alert organizations to critical vulnerabilities and potential exploits affecting control-system components. These advisories address a broad spectrum of products—from programmable logic controllers to remote...