Announcements

CVE-2026-60363 (matched: apache http server)

  • 22nd July 2026
A critical security vulnerability has been identified in the Apache Plugin component of Oracle HTTP Server, which is part of Oracle Fusion Middleware. The versions confirmed to be affected by this flaw are 12.2.1.4.0 and 14.1.2.0.0.This issue is easy to exploit, and does not require an attacker to have any login credentials or pre-existing access ...
Continue reading

CVE-2026-48687 (matched: php)

  • 22nd July 2026
A security flaw has been identified in FastNetMon Community Edition, affecting all versions up to 1.2.9, specifically in its Juniper router integration plugin. This is an OS command injection vulnerability, meaning unsanitized data passed to the plugin's logging script could be used to run unauthorized, potentially malicious commands on the server ...
Continue reading

CVE-2026-6722 (matched: php)

  • 22nd July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 22nd July 2026
DD-WRT is a popular open-source firmware installed on many third-party network routers, some of which you may use to connect your devices to your hosting service. A security vulnerability has been identified in this firmware: it contains a stack-based buffer overflow flaw, a type of coding weakness that can be exploited to run unauthorized, ...
Continue reading