In OpenWebUI versions 0.8.8 up to 0.11.0 a medium severity vulnerability CVE-2026-70490 was detected. This vulnerability allows an attacker to bypass user verification on terminal routes. To address this issue, users should upgrade OpenWebUI to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-70490.
Read more SecurityIn Wazuh versions prior to 4.14.5 a high severity vulnerability CVE-2026-28220 was detected. This vulnerability allows an authenticated actor to execute arbitrary code on the master node. To address this issue, users should upgrade Wazuh to version 4.14.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28220.
Read more SecurityIn Zeek versions before 8.0.9 a high severity vulnerability CVE-2026-60109 was detected. This vulnerability allows unauthenticated remote attackers to cause a denial of service. To address this issue, users should upgrade Zeek to version 8.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60109.
Read more SecurityIn OpenWebUI versions before 0.10.0 a high severity vulnerability CVE-2026-59214 was detected. This vulnerability allows attackers to execute server-side code through configured tools via authenticated same-origin requests. To address this issue, users should upgrade OpenWebUI to version 0.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59214.
Read more SecurityIn Traefik versions prior to v2.11.51, v3.6.22, and v3.7.6 a critical severity vulnerability CVE-2026-54763 was detected. This vulnerability allows attackers to bypass authentication by using underscore-variant header names. To address this issue, users should upgrade Traefik to version 2.11.51 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54763.
Read more SecurityIn Traefik versions before 2.10.5 and 3.0.0-beta4 a high severity vulnerability CVE-2023-54365 was detected. This vulnerability allows a remote attacker to rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability. To address this issue, users should upgrade Traefik to version 2.10.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-54365.
Read more SecurityIn Traefik versions 3.7.0-ea.1 to before 3.7.5 a medium severity vulnerability CVE-2026-54762 was detected. This vulnerability allows an unauthenticated attacker to access backend services that were intended to be protected, leading to an authentication bypass. This occurs in the Kubernetes Ingress NGINX provider due to a fail-open behavior. When an Ingress explicitly enables BasicAuth or DigestAuth through annotations, but the referenced auth-secret cannot be resolved or parsed (e.g., it is missing, malformed, or policy-denied), Traefik logs the error and skips installing the authentication middleware, while still routing traffic to the backend service. To address this issue, users should upgrade Traefik to version 3.7.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54762.
In RustDesk Client versions up to, including, 1.4.5 on Windows, MacOS, Linux, iOS, Android, and WebClient a high severity vulnerability CVE-2026-30792 was detected. This vulnerability allows an attacker to bypass local security settings and manipulate Application API messages via a Man-in-the-Middle (MitM) attack. This occurs because the client blindly merges unauthenticated strategy payloads received during synchronization. Specifically, the strategy merge loop (in src/hbbs_http/sync.Rs) and the Config::set_options() engine fail to properly authenticate or validate incoming configuration payloads before applying them. To address this issue, users should upgrade RustDesk Client to a patched version 1.4.6 or newer. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-30792.
In RustDesk Client versions up to, including 1.4.5 on Windows, MacOS, Linux, iOS, and Android a high severity vulnerability CVE-2026-30794 was detected. This vulnerability allows an attacker to perform Adversary in the Middle (AiTM) attacks and intercept sensitive communications. This occurs due to improper certificate validation in the HTTP API client; specifically, if an initial TLS handshake fails, the client attempts a retry using the danger_accept_invalid_certs(true) configuration in the TLS transport module, which silently accepts invalid TLS certificates. To address this issue, users should upgrade RustDesk Client to a patched version 1.4.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-30794.