Announcements

CVE-2026-6722 (matched: php)

  • 23rd July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in DD-WRT, a popular open-source firmware used for many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error that can cause a program to behave unexpectedly or run unauthorized instructions.The error exists in DD-WRT’s built-in UPnP (Universal Plug ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 23rd July 2026
We are notifying you of a security vulnerability identified in Langflow, a software tool that may be installed on some of your hosting accounts. The flaw allows anyone accessing your Langflow instance or connected site from the internet without your permission to run any code of their choosing on servers running the affected version of the tool.If ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in WordPress Core, the base software that powers all WordPress websites hosted on our platform. This flaw stems from an interpretation conflict in the WordPress codebase.If exploited by a bad actor, this issue could allow them to launch SQL injection attacks that target your site's private database, and ...
Continue reading