Announcements

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in the Langflow application, a tool some of our customers deploy on their hosted websites. This flaw is categorized as an inclusion of functionality from an untrusted control sphere issue. In practical terms, this vulnerability allows unauthorized remote users to run any custom code they choose on ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
A security flaw has been identified in the core WordPress software, the base platform that powers all standard WordPress websites. This issue, called an interpretation conflict vulnerability, could be exploited by bad actors to perform SQL injection attacks (injecting harmful commands into your site's database) and achieve remote code execution ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A SQL injection security flaw exists in WordPress core. This vulnerability is triggered when a plugin or theme you have installed passes untrusted, unvetted input to a specific site parameter. This flaw can be chained with the separate known vulnerability CVE-2026-63030 to allow attackers with no login access to your site to run their own code on ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 22nd July 2026
We’re sharing a security notice related to Microsoft SharePoint, a common platform many organizations use for document management, team collaboration, and internal content hosting. The service has a known flaw where it improperly processes untrusted, unvetted data sent to it. If a bad actor successfully exploits this flaw, they can run ...
Continue reading