Announcements

CVE-2026-49261 (matched: mariadb)

  • 13th August 2026
A security flaw has been identified in certain versions of MariaDB, a widely used open-source database software that powers many websites. If you run an affected version of MariaDB with the wsrep_notify_cmd setting turned on, an attacker could hide malicious system commands in the name of a new server that joins your database cluster, and those ...
Continue reading

Metabase Metabase: Metabase SQL Injection Vulnerability

  • 13th August 2026
If your website uses Metabase (a common tool for building custom data dashboards and reports tied to your site's information), there is a serious security flaw in this software you should be aware of. The vulnerability is a type of input flaw that lets unauthenticated remote attackers send malicious database commands directly to Metabase's ...
Continue reading

Microsoft Windows Ancillary Function Driver for WinSock : Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

  • 13th August 2026
A security vulnerability has been identified in the Windows Ancillary Function Driver for WinSock, a core Windows component that manages network functions for Windows servers. This is a use-after-free flaw, a type of memory management error. An attacker with already authorized local access to a Windows server could exploit this to gain elevated, ...
Continue reading

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

  • 13th August 2026
There is a newly identified security flaw in two Cisco firewall products (the Adaptive Security Appliance, or ASA, and Threat Defense, or FTD) that some of our clients use to protect their websites and online services.The flaw, categorized as a heap inspection vulnerability, can be triggered by an unauthenticated remote attacker — meaning no ...
Continue reading