Announcements

CVE-2026-44172 (matched: mariadb)

  • 28th July 2026
A security flaw, tracked as CVE-2026-44172, has been identified in specific older versions of MariaDB, a popular open-source database system used by many websites to store content, user data, and other site information.The issue affects MariaDB versions 3.3.18 and 3.4.8. Normally, a standard tool called mysql_real_escape_string() is designed to ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 28th July 2026
A security flaw has been identified in the on-premises version of Arista VeloCloud Orchestrator, a tool used to manage network and connected service operations. The flaw is an operating system command injection vulnerability, which allows a remote attacker to send specially crafted input to run unauthorized commands on the system that hosts the ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 28th July 2026
A security vulnerability has been identified in Fortinet FortiOS, a network security platform used by some organizations. This flaw could allow a remote attacker to access sensitive information they are not authorized to view, even without valid login credentials for the system. The attacker would carry this out by sending specially crafted web ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 28th July 2026
On July 20, 2026, Malaysia’s national cybersecurity agency (MyCERT) issued an advisory responding to new active exploitation attempts targeting Microsoft SharePoint, a popular platform many organizations use to host shared internal or public-facing website content. When SharePoint servers are successfully exploited, attackers can gain ...
Continue reading