Announcements

MA-1475.072026: MyCERT Advisory - Oracle E-Business Suite Improper Privilege Management Vulnerability

  • 25th July 2026
A security advisory was published by MyCERT on July 22, 2026, regarding a vulnerability in the Oracle E-Business Suite platform caused by improper privilege management. This flaw means the system may not correctly limit access to sensitive features, private business data, or administrative functions for users who are not authorized to use them. If ...
Continue reading

CVE-2026-23941 (matched: apache http server)

  • 25th July 2026
A security flaw tracked as CVE-2026-23941, known as HTTP Request Smuggling, has been identified in the inets httpd web server module, a component of the Erlang OTP software used by some hosting environments to handle web traffic. The flaw stems from how the server processes duplicate Content-Length headers in incoming web requests. The server uses ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 25th July 2026
We are sharing information about a recently disclosed security flaw in the NGINX JavaScript tool, which some websites use to run custom server-side scripting functions. This issue only impacts sites that use two specific features in combination: the js_fetch_proxy configuration that is set to use variables controlled by website visitors (such as ...
Continue reading