Application Security

Application Security
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
Application Security
Public Exploit Released for vBulletin CVE-2026-61511 RCE
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
Application Security
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Application Security
Fastjson CVE-2026-16723 Under Active Attack With No Patch
Fastjson CVE-2026-16723, a CVSS 9.0 Java RCE flaw with no patch, is under active attack against financial services, healthcare, computing, and retail targets.
Application Security
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
Application Security
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Poisoning
GitHub's new Dependabot 72-hour cooldown and PyPI's 14-day release lock target two supply chain attack vectors that compromised major package ecosystems.
Application Security
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Rockwell Automation patched four memory corruption CVEs in Arena, its simulation software used by hospitals, supply chain firms, and defense contractors.
Application Security
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA added SharePoint CVE-2026-58644, a CVSS 9.8 deserialization flaw, to KEV after Microsoft confirmed zero-day exploitation. Federal deadline is July 19.
Application Security
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Zoom patched CVE-2026-53412, a CVSS 9.8 flaw in Zoom Workplace for Windows allowing unauthenticated remote account takeover with no user interaction required.
Application Security
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.