Announcements

CVE-2026-4431 (matched: wordpress)

  • 5th August 2026
A security flaw has been identified in the Easy Post Submission plugin for WordPress, a tool often used to allow visitors to submit content to your site. This issue affects all versions of the plugin up to and including version 2.3.0. Normally, only authorized, logged-in users (such as your site administrators) should be able to edit existing ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 5th August 2026
A security flaw has been found in N-able N-central, a remote management platform some users rely on to oversee their IT and web infrastructure. This flaw allows attackers to bypass standard login requirements, which could let them gain unauthorized control over accounts on the platform. This issue stems from an earlier, incomplete fix for a ...
Continue reading

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 5th August 2026
A security flaw has been identified in IBM Langflow, a low-code tool commonly used to build and manage custom AI workflows. This is a code injection vulnerability: attackers do not need any login credentials or pre-authorized access to exploit the flaw on default Langflow deployments. If successfully exploited, an attacker can run any code they ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 5th August 2026
A security vulnerability has been found in Apache Tomcat. The flaw is a missing encryption of sensitive data issue, which means sensitive information processed by the platform is not secured as it should be.This vulnerability allows unauthorized parties to bypass the EncryptInterceptor, a built-in Tomcat security feature designed to protect ...
Continue reading