Monday , September 28 2026

Vulnerabilities

NVIDIA Patches High-Severity Flaws in AI Tools And Graphics

NVIDIA

NVIDIA has issued a dual security alert for developers and data scientists, announcing important updates for its Nsight Graphics and Merlin recommender system. Both vulnerabilities have a high CVSS score of 7.8 and can allow harmful code injection attacks that may compromise entire systems. The flaws jeopardize the tools needed …

Read More »

Oracle patched 337 flaws for over 30 products

Oracle released 337 security patches for more than 30 products in its January 2026 Critical Patch Update (CPU), targeting approximately 230 unique CVEs. Several patches fix CVE-2025-66516 (CVSS score 10/10), a serious Apache Tika vulnerability that may allow XML External Entity (XXE) injection. The vulnerability affects three Apache Tika modules …

Read More »

Zoom Critical Command Injection Vuln allows Remote Code Execution

command injection

A critical command injection flaw in Node Multimedia Routers (MMRs) may let meeting participants run arbitrary code on vulnerable systems. CVE-2026-22844 is a highly critical vulnerability with a CVSS score of 9.9, indicating an urgent need for immediate action. Zoom Command Injection Vulnerability: A command injection flaw is found in …

Read More »

GPT-5.2 Can Develop Zero-Day Exploits: Study unveils

exploit

Recent research shows that AI systems can now handle complex exploit development tasks that used to need specialized human skills. The agents had to create exploits while facing realistic challenges like modern security measures, unknown heap conditions, and restrictions on hardcoded memory addresses. In six scenarios focused on tasks like spawning …

Read More »

TP-Link Router Flaw Allows Auth Bypass Via Password Recovery Mechanism

password

A critical security flaw in TP-Link’s VIGI surveillance cameras allows attackers on local networks to change admin passwords without permission. CVE-2026-0629 identifies a critical flaw in the camera’s web interface password recovery, rated 8.7 on the CVSS v4.0 scale. The authentication bypass issue arises from incorrect client-side state handling in …

Read More »

Cisco 0-Day RCE Secure Email Gateway Vuln actively Exploited

Secure Email Gateway

Cisco has confirmed that a serious zero-day vulnerability allowing remote code execution is being actively exploited in its Secure Email Gateway and Secure Email and Web Manager appliances. The CVE-2025-20393 flaw lets unauthorized attackers run arbitrary root commands by sending specific HTTP requests to the Spam Quarantine feature. Cisco aware …

Read More »

Chrome 144 Released, Fixing 10 V8 Engine Vulnerabilities

Chrome 144

Google has released Chrome 144 for Windows, Mac, and Linux, fixing 10 security issues, mainly in the V8 JavaScript engine. The rollout is scheduled to reach users progressively over the coming days and weeks. Critical Security Patches for V8 Engine: Chrome version 144.0.7559.59 for Linux and 144.0.7559.59/60 for Windows and …

Read More »

Node.js Security Release Patches 7 Vulns Across Releases

Node.js

Node.js released security updates on January 13, 2026, fixing vulnerabilities that could cause memory leaks, denial-of-service attacks, and permission bypasses. These updates fix three critical vulnerabilities, among others, urging immediate upgrades for affected systems. High Severity Vulnerabilities: CVE-2025-55131 reveals critical flaws in Buffer.alloc and Uint8Array, resulting from timeout races in …

Read More »

Microsoft Patch Tuesday January 2026 addresses 3 zero-days and 114 flaws

January

Microsoft’s January 2026 updates address 114 vulnerabilities, including critical remote code execution bugs in Office apps and Windows services like LSASS. This Patch Tuesday fixes critical vulnerabilities that allow remote code execution and several privilege escalation problems that could let attackers take over systems. The number of bugs in each …

Read More »