In PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9 a critical severity vulnerability CVE-2026-17544 was detected. This vulnerability allows an attacker to cause an out-of-bounds write with stack and heap corruption. To address this issue, users should upgrade PHP to version 8.4.24 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-17544.
Read more Web DevelopmentIn koku-metrics-operator component for OpenShift in affected versions a high severity vulnerability CVE-2026-18381 was detected. This vulnerability allows a user to specify an arbitrary upload URL. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18381.
Read more Developer ToolsIn FuseWP component for WordPress versions 1.1.24.2 and earlier a medium severity vulnerability CVE-2026-5582 was detected. This vulnerability allows attackers to trick authenticated users into performing unintended actions. To address this issue, users should upgrade FuseWP to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5582.
Read more CMSIn SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery component for WordPress versions 3.9.7 and earlier a critical severity vulnerability CVE-2026-15014 was detected. This vulnerability allows an attacker to take over user accounts. To address this issue, users should upgrade SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15014.
Read more CMSIn SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery component for WordPress versions 3.9.7 and earlier a medium severity vulnerability CVE-2026-15670 was detected. This vulnerability allows authenticated attackers to extract sensitive information from the database. To address this issue, users should upgrade SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15670.
Read more CMSIn Apache ActiveMQ versions before 5.19.9, a high severity vulnerability CVE-2026-59878 was detected. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service. To address this issue, users should upgrade Apache ActiveMQ to version 5.19.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59878.
Read more Developer ToolsIn Apache Tomcat versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120 a high severity vulnerability CVE-2026-66299 was detected. This vulnerability allows attackers to cause uncontrolled resource consumption. To address this issue, users should upgrade Apache Tomcat to version 9.0.121 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-66299.
Read more Application DevelopmentIn Apache ActiveMQ versions before 5.19.9 a medium severity vulnerability CVE-2026-61487 was detected. This vulnerability allows an authenticated low-privilege user to bypass write permissions for message queues. To address this issue, users should upgrade Apache ActiveMQ to version 5.19.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-61487.
Read more Developer ToolsIn certain versions of Node a medium severity vulnerability CVE-2026-66922 was detected. This vulnerability allows an attacker to tamper with object prototypes, potentially leading to denial of service or other security bypasses. To address this issue, users should upgrade Node to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-66922.
Read more Developer Tools