In Foreman versions prior to 6.16.10 a high severity vulnerability CVE-2026-5136 was detected. This vulnerability allows attackers to gain unintended role permissions. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5136.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5135 was detected. This vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5135.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5138 was detected. This vulnerability allows an authenticated user with host-edit permissions to access information from other tenants. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5138.
Read more IT Business ManagementIn PHP a critical severity vulnerability CVE-2026-34116 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the server. To address this issue, users should upgrade PHP to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34116.
Read more Web DevelopmentIn Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109 a medium severity vulnerability CVE-2026-50229 was detected. This vulnerability allows a remote attacker to inject malicious scripts into the ‘number guess example’ web page. To address this issue, users should upgrade Apache Tomcat to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50229.
Read more Application DevelopmentIn Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, and 8.5.0 through 8.5.100 a high severity vulnerability CVE-2026-53404 was detected. This vulnerability allows attackers to bypass security constraints if rewrite rules are used for access control. To address this issue, users should upgrade Apache Tomcat to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-53404.
Read more Application DevelopmentIn Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.13 through 9.0.18, 8.5.38 through 8.5.100, and 7.0.100 through 7.0.109 a medium severity vulnerability CVE-2026-55955 was detected. This vulnerability allows a replay attack against the EncryptionInterceptor in the cluster component. To address this issue, users should upgrade Apache Tomcat to version 9.0.119 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55955.
Read more Application DevelopmentIn Webmention component for WordPress versions 5.8.0 and earlier a high severity vulnerability CVE-2026-10513 was detected. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. To address this issue, users should upgrade Webmention to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10513.
Read more CMSIn JetWidgets For Elementor component for WordPress versions 1.0.21 and earlier a medium severity vulnerability CVE-2026-11380 was detected. This vulnerability allows attackers to inject malicious scripts. To address this issue, users should upgrade JetWidgets For Elementor to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11380.
Read more CMS