● On the wire
Cisco Advance Notification for Publication of September 2, 2026, Security Advisories//I pointed an agent at a bootloader. It found bugs but not useful ones//Debian OpenSSL Denial of Service DSA-6465-1 CVE-2026-14456 CVE-2026-14457//Debian xrdp Advisory DSA-6469-1 Multiple Threats CVE-2026-32105//Ubuntu 26.04 OpenJDK 17 Security Issues - USN-8676-1 - Multiple Threats//Ubuntu 24.04 libheif Critical Buffer Overflow Security Updates USN-8683-1//ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)//Critical Denial of Service Vulnerabilities in Ubuntu OpenJDK 8 USN-8673-1//Ubuntu OpenSSL Important Denial of Service Vulnern USN-8678-2//“CNA Rules v4.2.0” Now in Effect//Breaking Claude Code Opus 5 Auto Mode//Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)//Debian FreeCAD Critical Code Exec Local File Disclosure DSA-6467-1//Debian Emacs Critical Code Exec DoS Issue DSA-6468-1 CVE-2026-6861//ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)//Cisco Advance Notification for Publication of September 2, 2026, Security Advisories//I pointed an agent at a bootloader. It found bugs but not useful ones//Debian OpenSSL Denial of Service DSA-6465-1 CVE-2026-14456 CVE-2026-14457//Debian xrdp Advisory DSA-6469-1 Multiple Threats CVE-2026-32105//Ubuntu 26.04 OpenJDK 17 Security Issues - USN-8676-1 - Multiple Threats//Ubuntu 24.04 libheif Critical Buffer Overflow Security Updates USN-8683-1//ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)//Critical Denial of Service Vulnerabilities in Ubuntu OpenJDK 8 USN-8673-1//Ubuntu OpenSSL Important Denial of Service Vulnern USN-8678-2//“CNA Rules v4.2.0” Now in Effect//Breaking Claude Code Opus 5 Auto Mode//Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)//Debian FreeCAD Critical Code Exec Local File Disclosure DSA-6467-1//Debian Emacs Critical Code Exec DoS Issue DSA-6468-1 CVE-2026-6861//ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)//
CISA inserisce Oracle HTTP Server/WebLogic Proxy Plug-in nel catalogo KEV per sfruttamento attivo
Top story — News

CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation

CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability that can be exploited remotely via HTTP without credentials. An attacker with network access can read, modify, or delete critical data and, in some scenarios, gain…

Read the article →
From the newsroom
Spotlight
More news