Security news, decoded.
What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.
Critical Rclone Command Execution Bug Threatens Cloud Environments
Critical Veeam Backup Vulnerability Exposed
Critical FortiSandbox Flaw Requires Immediate Patching
Critical TinyMCE Cross Site Scripting Flaws Threaten Millions of Applications
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
MBS Universal Gateway Flaws Threaten Building Automation Networks
MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6005 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6007 immediately to reduce the likelihood of compromise.