Announcements

CVE-2026-6722 (matched: php)

  • 22nd July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 22nd July 2026
DD-WRT is a popular open-source firmware installed on many third-party network routers, some of which you may use to connect your devices to your hosting service. A security vulnerability has been identified in this firmware: it contains a stack-based buffer overflow flaw, a type of coding weakness that can be exploited to run unauthorized, ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in the Langflow application, a tool some of our customers deploy on their hosted websites. This flaw is categorized as an inclusion of functionality from an untrusted control sphere issue. In practical terms, this vulnerability allows unauthorized remote users to run any custom code they choose on ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
A security flaw has been identified in the core WordPress software, the base platform that powers all standard WordPress websites. This issue, called an interpretation conflict vulnerability, could be exploited by bad actors to perform SQL injection attacks (injecting harmful commands into your site's database) and achieve remote code execution ...
Continue reading