Announcements

Microsoft SharePoint: Microsoft SharePoint Weak Authentication Vulnerability

  • 21st August 2026
A security flaw has been identified in Microsoft SharePoint, a common tool many website owners use to build team collaboration spaces, share files, and manage custom hosted site features.The issue is a weak authentication vulnerability, meaning the system’s built-in check to confirm only approved users can access protected parts of a SharePoint ...
Continue reading

Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerability

  • 21st August 2026
A security flaw has been identified in Broadcom VMware vCenter, a tool commonly used to manage virtual server hosting environments. This is a path traversal vulnerability, a type of weakness that lets an unauthorized party access protected parts of the system they would not normally be able to reach. If a bad actor has access to the network your ...
Continue reading

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 21st August 2026
A security vulnerability has been identified in Microsoft's Internet Key Exchange (IKE) Service Extensions, a component used to manage secure network connections for devices and online services. The flaw stems from a coding error called a "double free," which occurs when a system accidentally tries to free the same block of computer memory twice, ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 21st August 2026
A security flaw has been found in MLflow, a tool used to manage machine learning projects and related workflows. This flaw is a server-side request forgery (SSRF) vulnerability, meaning attackers can trick the MLflow service into sending unauthorized requests on its own behalf.This vulnerability lets bad actors use an affected MLflow instance to ...
Continue reading