Articles
Newsflash
28 Jul 2026 Data Management and Analytics
Apache Airflow: Privilege Escalation Vulnerability

In Apache Airflow versions prior to 3.7.2 a high severity vulnerability CVE-2026-59245 was detected. This vulnerability allows a low-privileged user to escalate privileges and gain read/edit access to all DAGs. To address this issue, users should upgrade Apache Airflow to version 3.7.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59245.

Read more
Data Analytics
28 Jul 2026 Data Management and Analytics
Apache Airflow: Disabled SSH Host-Key Verification in Git provider

In the Git provider component for Apache Airflow versions 0.4.0 and earlier a high severity vulnerability CVE-2026-58065 was detected. This vulnerability allows a man-in-the-middle attacker to intercept credentials and inject malicious content. To address this issue, users should upgrade the Git provider to version 0.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-58065.

Read more
Data Analytics
28 Jul 2026 DevOps
OpenShift: Privilege Escalation Vulnerability

In OpenShift earlier versions a high severity vulnerability CVE-2026-15584 was detected. This vulnerability allows an attacker to escalate privileges and gain root access on cluster nodes. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-15584.

Read more
Developer Tools
28 Jul 2026 Business and Enterprise Solutions
WordPress: Sensitive Information Exposure in Smart Slider 3

In Smart Slider 3 component for WordPress versions 3.5.1.37 and earlier a medium severity vulnerability CVE-2026-12385 was detected. This vulnerability allows authenticated attackers to extract titles and full content excerpts of various types of posts. To address this issue, users should upgrade Smart Slider 3 to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12385.

Read more
CMS
28 Jul 2026 Business and Enterprise Solutions
WordPress: Stored Cross-Site Scripting in Avada (Fusion) Builder

In Avada (Fusion) Builder component for WordPress versions 3.15.5 and earlier a medium severity vulnerability CVE-2026-12536 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Avada (Fusion) Builder to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-12536.

Read more
CMS
27 Jul 2026 Business and Enterprise Solutions
WordPress: Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in Breeze Cache

In Breeze Cache component for WordPress versions before 2.5.6 a medium severity vulnerability CVE-2026-10551 was detected. This vulnerability allows an attacker to inject arbitrary HTML attributes in the final HTML output. To address this issue, users should upgrade Breeze Cache to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-10551.

Read more
CMS
Case Studies