Dell patches Secure Connect Gateway flaws - but is CVE-2026-79941 really 'critical'?
A newly listed Dell bug is tagged critical severity despite carrying a CVSS score that normally means 'medium' - here's what's actually confirmed.
Breaches, vulnerabilities, privacy and staying safe online.
A newly listed Dell bug is tagged critical severity despite carrying a CVSS score that normally means 'medium' - here's what's actually confirmed.
A newly catalogued bug in the popular remote-access tool has US federal agencies scrambling to patch by Monday, though who's behind the attacks and how remains unclear.
A newly disclosed flaw in the Netis NX10 lets unauthenticated attackers read the admin password straight off the web interface - but the headline 9.8 score doesn't match what the researcher's own advisory says.
CISA says CVE-2026-86060 is being used in real attacks against MikroTik routers, yet neither the agency nor NVD has published what the bug actually does.
A newly catalogued flaw scores a near-maximum 9.9 for severity, but the fine print matters more than the number.
A new NetScaler bug has made the US government's most urgent watchlist, yet nobody outside CISA seems to know exactly how it's being abused.
No money went missing at these four charities, the regulator says, but blank cheques and weak oversight were enough to earn a formal finding of mismanagement - and the bigger 105-charity inquiry grinds on.
A near-maximum severity score sounds terrifying, but the catch is who actually owns one of these boxes - and whether Advantech has fixed it yet.
A newly catalogued Adobe Commerce and Magento bug is already being exploited, says CISA, though it's telling us very little about how.
A hobby project spent 61 hours of desktop compute breaking encryption that Netscape itself gave up on in 2002 - here's why nobody today should lose sleep over it.
A missing environment variable is all it takes to bypass authentication entirely — but only if you've actually installed the thing.
CISA says attackers are already using CVE-2026-82329 in the wild, but the public record is short on detail about how it works and who exactly is exposed.
A newly disclosed bug in excel-mcp-server scores a maximum-alarm 9.8 out of 10 - but the danger depends entirely on a setting most people won't have touched.
CVE-2026-49869 has landed on America's known-exploited-vulnerabilities list with a three-day patch deadline for federal agencies, yet neither CISA nor NVD have published what the bug actually does.
A newly disclosed bug in the Python framework Taipy scores a near-maximum severity rating - but whether it's actually being exploited, or even patched, is still an open question.
A vulnerability in a widely used Python web framework has made America's most-watched vulnerability list, yet the public record is oddly thin on what the bug actually does.
A sandbox-escaping bug in every version of Chromium is under active attack, but the size of the bounty is raising more eyebrows than the bug itself.
A newly logged bug scores a maximum-alarm 9.9 out of 10, but the fine print matters more than the number.
CISA says CVE-2026-85046 is being exploited right now, yet the public record barely tells us what the bug does or which Chrome version fixes it.
A newly listed flaw in Firefox Focus for Android carries a maximum-alarm score, yet Mozilla's own paperwork barely says what it actually does.
CISA says the flaw is being exploited right now, but its own listing is oddly light on what the bug actually does or who's behind the attacks.
A flaw in a niche policy-checking package let attackers hide dangerous wildcard rules from GitHub's cloud login guardrails, but only a small slice of DevOps setups will ever encounter it.
CISA says CVE-2026-81578 is being actively exploited in the wild, yet the public record offers almost nothing on how the attack actually works.
A maximum-severity bug in the argocd-mcp server skipped login checks entirely - but only if you'd switched it on and pointed it at the open network in the first place.
CISA says CVE-2026-82078 is being exploited right now, yet the public record says almost nothing about how, by whom, or whether a fix even exists.
A critical-rated flaw in the Kafka-alternative streaming platform boils down to an insecure default, not some exotic exploit - but that doesn't make it harmless.
A 9.8-rated bug can forge fingerprint checks in a niche identity tool called openssl_encrypt - which, despite the name, has nothing to do with the actual OpenSSL library.
CISA says CVE-2026-66384 is being exploited in the wild right now, yet the public record barely says what it actually does.
A flaw in the little-used openssl_encrypt package could let an attacker fake a trusted contact's key - but the 'critical' label needs a reality check.
CISA says CVE-2026-53362 is being used in real attacks right now, yet the public record is almost entirely blank on what the bug actually does.
CVE-2026-16286 lets attackers upload dangerous files to TRtek's Software Repository Management tool, yet the advisory says nothing about a fix, active abuse, or how many people actually run it.
CISA has flagged CVE-2023-49105 as under real-world attack, but the small print matters: this is a federal-agency deadline, not a nationwide emergency.
CVE-2021-23758 has just landed on America's most-watched vulnerability list, five years after it was first catalogued, and the public record explains almost nothing about how it's being abused.
A Python HTML-sanitiser has patched several sanitisation bypasses - but the severity score depends entirely on who you ask, and mostly on how you've configured it.
America's cyber-security agency says a bug in the popular self-hosted Git platform Gitea is already being used in real attacks, yet the public record barely explains what it actually does.
A stack overflow in a niche WiFi access point has been rated maximum severity, though the number attached to it deserves more scrutiny than the bug itself.
CVE-2026-21962 scores a perfect 10 out of 10 and is already being exploited in the wild - but this is squarely an enterprise problem, not one for home users.
One person's viral blog post shows how far AI-assisted reverse engineering has come, but this is a personal experiment, not a security alert for the rest of us.
A newly published CVE rates 9.8 out of 10, but before anyone panics it's worth asking who actually runs this plugin, and whether it's even fixed yet.
A critical bug in vCenter's Syslog server has earned a place on America's most-wanted vulnerability list, but the scarier detail, Chinese hackers, hundreds of victims, comes from a blog post, not CISA.
A 9.1-rated bug sounds terrifying, but check who's actually running this before you panic - it's not your laptop.
A critical flaw in a Russian videoconferencing platform is being actively abused, but unless you're running TrueConf's server software yourself, this one passes you by.
CVE-2026-70496 hands a helper component cluster-admin-level powers on paper, but Red Hat's own rating and the fine print tell a calmer story.
A serious, unauthenticated bug in Zimbra Collaboration Suite is already being exploited, but only a specific, non-default setup is actually exposed.
The security regulator has issued a solidarity statement, not a policy change, here's what's actually new and what isn't.
A newly disclosed WebAssembly flaw in Firefox scores near the top of the danger scale, though Mozilla's own rating and the lack of any known attacks tell a calmer story.
A critical bug in the self-hosted video conferencing platform is now on the US government's confirmed-exploited list, but this is an enterprise problem, not a household one.
A stack overflow in a bundled nginx binary has earned the maximum CVSS score, but the affected device is a niche, ageing wireless controller rather than anything on your desk.
A validation gap in MLflow's webhook testing feature can be abused to sneak past security checks and reach internal systems, and someone is already doing it.
A 9.1-rated bug sounds terrifying, but check the small print: you need admin-level access to abuse it in the first place.
A 9.8-rated bug in Microsoft's IKE service lets attackers run code with no clicks and no credentials, and it's already being used in the wild, not just theorised.
The regulator's own risk assessment shows a real rise in cases, but that's likely as much about better detection as it is about scarier criminals.
A critical authentication bypass has been logged against a single Tenda AC10 firmware build - here's what's actually confirmed and what's still guesswork.
A browser trick and some old-fashioned DNS trickery can apparently hijack machines running Ray in dev mode, but only if you're the kind of person running Ray in dev mode.
A scoring of 9.8 sounds terrifying, but the flaw only bites sites running Grav's API plugin with super-user API keys already in play - here's what actually happened and who needs to patch.
A critical bug lets attackers run commands on LoadMaster boxes with no login required, but this is an enterprise networking story, not one for home routers.
CVE-2026-68820, a use-after-free bug in the WinSock driver, lets someone already on your PC escalate to SYSTEM. CISA has told federal agencies to patch by 25 August. Here is who is actually at risk, and who is not.
CVE-2026-68820 is a privilege escalation in a Windows networking driver. It cannot get an attacker in, which is the point: it is what they use once they are already there.
CVE-2026-20349 lets an unauthenticated attacker reboot a Cisco firewall from the internet. It does not steal anything, which is exactly why it is easy to underrate.
Two Cisco Secure Firewall products were added to the US catalogue of actively exploited vulnerabilities on 11 August, with a deadline of 14 August. The short clock is the tell.
The identity firm has passed a Kantara audit covering Right to Work, Right to Rent and DBS checks. Its announcement also claims the government has ended its digital ID scheme, which is not what happened.