CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Earlier39 stories
Jun 10
The Hacker News Research protobuf.js rce5 min read

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.

Jun 10
Daily CyberSecurity (securityonline.info) PoC Ivanti Sentry rce4 min read

Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10

Ivanti has published urgent fixes for its gateway appliances after researchers and watchTowr Labs disclosed a publicly available proof of concept for an Ivanti Sentry remote code execution issue. The affected component is associated with CVE-2026-10520 (CVSS 10), and a related authentication/privilege bypass is tracked as CVE-2026-10523 (CVSS 9.9), which can enable creation of administrative accounts and full administrative access. Because these systems sit at the edge of corporate traffic, unpatched deployments face a heightened risk of full administrative compromise; organizations should review logs and upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.

Jun 10
Daily CyberSecurity (securityonline.info) Patch OpenSSL patch-tuesday6 min read

OpenSSL Security Patches Fix Remote Code Execution Risk

OpenSSL has released emergency security updates to fix multiple memory-safety flaws in its certificate and QUIC-related code paths, including a use-after-free that can be triggered remotely and lead to Remote Code Execution via CVE-2026-45447. The release also covers additional security issues such as input-validation weaknesses (CVE-2026-34182), nonce handling problems in AES-OCB one-shot operations (CVE-2026-45445), and denial-of-service and crash conditions in the QUIC stack (CVE-2026-34183, CVE-2026-42764, CVE-2026-42765) plus an OCSP stapling double-free hazard (CVE-2026-35188). OpenSSL users are urged to upgrade promptly—e.g., from version 4.0 to version 4.0.1, and from 1.1.1 to 1.1.1zh—because unauthenticated attackers may be able to exploit these problems over the network.

Jun 10
Daily CyberSecurity (securityonline.info) Exploited Cisco Catalyst SD-WAN Manager zero-day4 min read

CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws

The US CISA has updated its Known Exploited Vulnerabilities catalog/active exploit list by adding three newly identified, in-the-wild flaws. Affected products include Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), and Google Chromium (CVE-2026-11645), spanning command-injection, tunneling/decapsulation weaknesses, and memory-safety issues that can lead to remote code execution. Because attackers are already targeting these weaknesses, organizations should prioritize patching and remediation immediately.

Jun 10
Daily CyberSecurity (securityonline.info) Advisory MBS Universal Gateway auth-bypass4 min read

MBS Universal Gateway Flaws Threaten Building Automation Networks

MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6005 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6007 immediately to reduce the likelihood of compromise.