Announcements

CVE-2026-65883 (matched: php)

  • 6th August 2026
A security vulnerability has been identified in the Joomla extension Aimy Captcha-Less Form Guard, versions 18.0 through 20.0, distributed by aimy-extensions.com. The flaw is triggered when a specially crafted entry is sent to the extension’s “clfgd” input field. This allows an attacker to inject malicious PHP code and carry out remote code ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 6th August 2026
A security vulnerability has been identified in N-able N-central, a platform many businesses use to remotely manage their company computers, servers, and other IT systems. The flaw allows attackers to bypass normal login requirements by using a hidden, alternate access route, which can lead to full account takeover of N-able N-central ...
Continue reading

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 6th August 2026
A serious security vulnerability has been identified in IBM Langflow, a workflow automation tool that some customers host on their web hosting accounts. The flaw allows unauthenticated attackers (people who do not have a valid login for the Langflow instance) to run any code they choose on default Langflow deployments, giving them full control of ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 6th August 2026
A security vulnerability has been identified in Apache Tomcat, a popular tool used to run many websites, including those hosted on our platform. The flaw involves a failure to properly encrypt sensitive data, which allows unauthorized parties to bypass a built-in security feature called the EncryptInterceptor that is intended to protect this ...
Continue reading