Announcements

CVE-2026-46420 (matched: php)

  • 18th August 2026
A security flaw has been found in setup-php, a common tool used to configure PHP environments for automated tasks run via GitHub Actions (a service many teams use for automated workflows like site testing and deployments). The flaw affects all versions of the tool from 2.25.0 up to 2.37.0.The vulnerability works because the tool reads PHP version ...
Continue reading

CVE-2019-11049 (matched: php)

  • 18th August 2026
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.Source: NVD (National Vulnerability Database) — ...
Continue reading

Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability

  • 18th August 2026
A security flaw has been identified in Ray, a tool some website developers use to build and test their projects. This is a code injection vulnerability, meaning bad actors could exploit it to run unauthorized, harmful code on any system where Ray is installed.The vulnerability can be exploited by attackers using Firefox or Safari web browsers. If ...
Continue reading

Apple macOS: Apple macOS Improper Authentication Vulnerability

  • 18th August 2026

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-65400

Continue reading