
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center

Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center

FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen

Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it

Kiteworks patched a maximum-severity code injection flaw found through its bug bounty program, marking its second critical disclosure in roughly

Cisco patched a critical authentication bypass in Catalyst SD-WAN Manager, formerly vManage, that attackers are actively exploiting to seize full

TeamViewer patched a critical access-control bypass and four other flaws in its Full Client and Host software, urging all users

WatchGuard patched a critical Fireware OS flaw letting a rogue VPN server run root commands on Firebox appliances, plus 14

CISA warned that a pre-authentication flaw in MikroTik RouterOS lets a single crafted request trigger root code execution or crash

OpenSSL patched a high-severity DTLS flaw that can expose unencrypted heap memory or crash affected software running its widely used

Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.