Announcements

CVE-2026-60363 (matched: apache http server)

  • 24th July 2026
A critical security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The affected versions of this software are 12.2.1.4.0 and 14.1.2.0.0. This flaw is easy to exploit, and requires no login credentials or special access for an attacker to use it. Anyone who can send standard ...
Continue reading

CVE-2026-23941 (matched: apache http server)

  • 24th July 2026
A security flaw has been found in the inets httpd web server module included with Erlang OTP, a software platform some websites use to process web traffic. The issue is classified as HTTP request smuggling, a type of vulnerability that can let attackers sneak unauthorized commands or data into legitimate visitor traffic to bypass a website's ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 24th July 2026
A security vulnerability has been identified in the NGINX JavaScript feature. This issue only impacts sites that have the js_fetch_proxy setting configured to pull data from parts of incoming web requests that visitors can control (such as URL parameters, cookies, or custom HTTP headers) and that also use the ngx.fetch() function from NGINX ...
Continue reading