Monday, April 27, 2026
HomeTagsVulnerability

Tag: Vulnerability

CISA Alerts on D-Link Path Traversal Vulnerability Being Actively Exploited in Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical D-Link router vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation of a path traversal vulnerability that affects legacy DIR-859 router models. The vulnerability, tracked as CVE-2024-0769, enables attackers to...

IBM i Vulnerability Enables Attackers to Gain Elevated Privileges

IBM has disclosed a critical security vulnerability affecting multiple versions of its IBM i operating system that could enable attackers to gain elevated privileges through an unqualified library call vulnerability. The vulnerability, tracked as CVE-2025-36004, carries a high CVSS base score of 8.8 and...

ClamAV Versions 1.4.3 and 1.0.9 Launch with Patch for Remote Code Execution Vulnerability

Today marks a significant milestone for the open-source antivirus community as ClamAV releases versions 1.4.3 and 1.0.9. These patch releases address critical security vulnerabilities, including a dangerous buffer overflow that could enable remote code execution, along with several other important fixes and architectural improvements....

Realtek Vulnerability Allows DoS Attack via Bluetooth Pairing

A critical denial-of-service vulnerability in Realtek's RTL8762E SDK v1.4.0 that affects Bluetooth Low Energy (BLE) secure connections. The vulnerability allows attackers to disrupt the pairing process by exploiting improper state machine validation, potentially rendering affected devices unable to establish secure BLE connections. The vulnerability...

Kubernetes NodeRestriction Vulnerability Bypasses Resource Allocation Authorization

A newly disclosed security vulnerability in Kubernetes has been identified that allows compromised nodes to bypass critical authorization checks in the NodeRestriction admission controller. The vulnerability, tracked as CVE-2025-4563 and published to the GitHub Advisory Database just two days ago, affects recent versions of...

Critical Kibana Vulnerability Enable Heap Corruption and Remote Code Execution

A critical security vulnerability has been identified in Elastic's Kibana platform that enables attackers to execute heap corruption and potentially achieve remote code execution through specially crafted HTML pages. The vulnerability, designated as CVE-2025-2135 and detailed in Elastic Security Advisory ESA-2025-09, affects a wide...