
SonicWall Patches CVSS 10.0 Pre-Auth SSRF in SMA1000 Appliances
SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has

SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has

JFrog disclosed CVE-2026-105192, a CVSS 9.8 pickle deserialization flaw in LMCache that lets one network message run code. No patched

Google released Chrome 155 with fixes for 247 vulnerabilities, four of them critical use-after-free flaws. Google reports no in-the-wild exploitation.

Attackers probed Atlassian Data Center flaw CVE-2026-21589 within two hours of watchTowr publishing details; Previdian logged 15 attempts from three

Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four

Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and

Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code

Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as

Google’s Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.

CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.