Announcements

CVE-2026-17544 (matched: php)

  • 6th August 2026
A security flaw has been identified in specific versions of PHP, the software that powers many dynamic websites. The flaw impacts PHP 8.4 releases older than version 8.4.24, and PHP 8.5 releases older than version 8.5.9.The issue is triggered when an attacker sends specially crafted input to a PHP function used for comparing large decimal numbers, ...
Continue reading

CVE-2026-17543 (matched: php)

  • 6th August 2026
A security flaw tracked as CVE-2026-17543 has been identified in specific versions of PHP, the widely used software that powers most dynamic websites. The issue stems from improper handling of backslashes in data submitted by visitors to your site.This flaw enables trivial SQL injection attacks, which let bad actors access, modify, or delete the ...
Continue reading

CVE-2026-65883 (matched: php)

  • 6th August 2026
A security flaw has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, created by aimy-extensions.com, that impacts versions 18.0 through 20.0. This issue lets attackers use a specially crafted entry in the form’s "clfgd" field to run their own malicious code directly on your website, a type of attack known as remote code ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 6th August 2026
A security vulnerability has been identified in the N-able N-central remote management platform. This flaw lets attackers use an alternate access path or channel to bypass normal login requirements, allowing them to access and take over user accounts on the service without needing valid credentials.This issue stems from an incomplete patch for an ...
Continue reading