Announcements

CVE-2026-65883 (matched: php)

  • 5th August 2026
This security notice is for owners of Joomla websites that use the Aimy Captcha-Less Form Guard extension (versions 18.0 to 20.0) from aimy-extensions.com. A flaw exists in these specific extension versions: attackers can exploit it by sending a specially crafted entry to the "clfgd" field on forms powered by this tool.If this flaw is exploited, ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 5th August 2026
A security vulnerability has been found in N-able N-central, a remote management tool many organizations use to oversee their servers, websites, and IT systems. The flaw lets attackers bypass the platform’s normal login requirements, which could allow them to take over user accounts linked to N-central.This issue exists because an earlier patch ...
Continue reading

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 5th August 2026
A security flaw has been identified in IBM Langflow, a tool some website and project owners use to build and manage automated workflows. The issue is a code injection vulnerability, a type of security gap that allows unauthorized parties to run their own malicious code on affected systems.This flaw is particularly risky because attackers do not ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 5th August 2026
Apache Tomcat is a common open-source tool used to run Java-based websites and web applications. A vulnerability has been identified in this tool: it fails to properly encrypt sensitive data it processes, which allows bad actors to bypass the EncryptInterceptor security feature that is built in to protect that private information.If your website ...
Continue reading