Announcements

CVE-2026-60363 (matched: apache http server)

  • 22nd July 2026
A critical security vulnerability has been identified in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically in its Apache Plugin module. This issue affects versions 12.2.1.4.0 and 14.1.2.0.0, and has a severity rating of 9.8 out of 10 on the standard CVSS security scale. This flaw is easily exploitable: an attacker does not ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in DD-WRT, software used in some network devices connected to your hosting setup. The flaw is a stack-based buffer overflow, a type of issue that occurs when a program receives more data than its temporary memory storage can safely handle. This specific vulnerability targets the internal buffer used by ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 22nd July 2026
A recent security advisory highlights a critical flaw in Langflow, a platform some hosting clients use to build low-code automated workflows and custom tools for their websites. This issue is categorized as an inclusion of functionality from an untrusted control sphere vulnerability, which means remote attackers can remotely send and run ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
A security flaw has been identified in WordPress Core, the base software that powers WordPress websites. This is an interpretation conflict vulnerability that could be exploited by attackers to carry out SQL injection attacks and gain remote control of your website. SQL injection attacks let bad actors access, modify, or delete data stored in your ...
Continue reading