Announcements

Broadcom VMware vCenter: Broadcom VMware vCenter Path Traversal Vulnerability

  • 20th August 2026
A security vulnerability has been discovered in Broadcom VMware vCenter, a platform widely used to manage virtual server environments. This flaw is a path traversal issue, a type of security gap that can allow unauthorized users to access restricted parts of the system's file structure.If a bad actor has network access to an affected vCenter ...
Continue reading

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 20th August 2026
A security flaw has been identified in Microsoft’s Internet Key Exchange (IKE) Service Extensions, a component built into Windows server systems that handles secure network and VPN connections. This flaw is categorized as a double free vulnerability. If a remote attacker is able to successfully exploit it, they could run unauthorized, harmful ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 20th August 2026
A security flaw has been identified in MLflow, a tool many website owners use to manage machine learning workflows on their hosting accounts. This flaw is a server-side request forgery (SSRF) vulnerability, which lets attackers use your MLflow setup to send requests to systems that are supposed to be private and not accessible from the public ...
Continue reading

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 20th August 2026
A security vulnerability has been found in TrueConf Server, a software platform some hosting clients may run on their accounts. The flaw occurs because a critical function of the software does not require proper login verification to access, meaning no valid account credentials are needed to interact with this part of the system.An unauthorized ...
Continue reading