Announcements

CVE-2026-60363 (matched: apache http server)

  • 24th July 2026
A critical security vulnerability, identified as CVE-2026-60363, has been discovered in the Apache Plugin component of Oracle HTTP Server, which is part of Oracle Fusion Middleware. The affected software versions are 12.2.1.4.0 and 14.1.2.0.0.This flaw is simple to exploit and does not require an attacker to have valid login credentials for your ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 24th July 2026
A security vulnerability has been identified in NGINX JavaScript, a component used in many web server setups. This flaw only affects sites that have the js_fetch_proxy setting configured to use visitor-supplied data (such as URL parameters, cookies, or custom request headers) alongside the ngx.fetch() operation in their NGINX JavaScript code. If ...
Continue reading

CVE-2026-44172 (matched: mariadb)

  • 24th July 2026
A security vulnerability has been identified in MariaDB server, a popular open-source database system commonly used to store and manage website data, in versions 3.3.18 and 3.4.8.This flaw creates a gap in protection against SQL injection attacks, a common threat where bad actors tamper with database queries to steal, alter, or delete website and ...
Continue reading

CVE-2026-15981 (matched: php)

  • 24th July 2026
A security flaw has been found in the SAML Single Sign On (SSO Login) plugin for WordPress, impacting all versions up to and including 5.4.4.The issue lies in how the plugin checks if incoming SSO login requests are authentic. A bug in its signature verification process causes malformed, fake login requests to be incorrectly marked as valid. This ...
Continue reading