Articles
Newsflash
30 Sep 2026 DevOps
NGINX: Heap Buffer Overflow in ngx_http_v3_module

In ngx_http_v3_module component for NGINX in certain versions a medium severity vulnerability CVE-2026-90439 was detected. This vulnerability allows for a potential limited heap buffer overflow while processing a TLS handshake. To address this issue, users should upgrade NGINX to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90439.

Read more
Application Development
30 Sep 2026 DevOps
Python: Remote Code Execution and token theft in Google Cloud Gemini Enterprise Agent Platform SDK

In Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 a high severity vulnerability CVE-2026-19407 was detected. This vulnerability allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. To address this issue, users should upgrade the Google Cloud Gemini Enterprise Agent Platform SDK for Python to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19407.

Read more
Application Development
30 Sep 2026 Business and Enterprise Solutions
WordPress: Cross-Site Scripting vulnerability in MotoPress Hotel Booking plugin

In MotoPress Hotel Booking plugin component for WordPress versions 6.2.4 and earlier a high severity vulnerability CVE-2026-90650 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade MotoPress Hotel Booking plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90650.

Read more
CMS
30 Sep 2026 Data Management and Analytics
Fluentd: Resource Exhaustion Vulnerability in fluent-plugin-opentelemetry

In fluent-plugin-opentelemetry component for Fluentd versions prior to 0.5.3 a medium severity vulnerability CVE-2026-44163 was detected. This vulnerability allows attackers to cause resource exhaustion by sending a large, compressed payload. To address this issue, users should upgrade fluent-plugin-opentelemetry to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44163.

Read more
Data Analytics
30 Sep 2026 Project and Agile Management
Kimai: Cross-Site Request Forgery Vulnerability

In Kimai versions prior to 2.58.0 a medium severity vulnerability CVE-2026-52823 was detected. This vulnerability allows an attacker to perform unauthorized actions by tricking an authenticated user into visiting a malicious link. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52823.

Read more
Project Management
29 Sep 2026 Business and Enterprise Solutions
WordPress: Arbitrary Script Injection in GenieWords

In GenieWords component for WordPress versions 1.5.34 and earlier a high severity vulnerability CVE-2026-74933 was detected. This vulnerability allows unauthenticated users to overwrite its configuration and inject arbitrary web scripts. To address this issue, users should upgrade GenieWords to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-74933.

Read more
CMS
Case Studies