Fortinet, Ivanti, and SAP patched critical flaws up to CVSS 10.0, reducing RCE, admin takeover, and data exposure risks.
Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.
Fortinet warns of a critical security vulnerability in FortiSandbox and other leaks in FortiPortal and FortiOS/FortiProxy.
CISA added CVE-2026-42271, a high-severity LiteLLM command injection flaw, to its KEV catalog after evidence of active ...
Universal Robots urges users to update PolyScope software following critical vulnerability ...
Two vulnerabilities in the secure mobile gateway appliance allow unauthenticated attackers to bypass authentication and ...
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added three new flaws in its Known Exploited Vulnerabilities (KEV) catalog, including a critical OS command injection impacting ...