USN-7001-1: Linux kernel critical security update
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.
The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM.
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00
CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.
After reimplementing SQLite in Rust, Turso is turning its attention to Postgres support. The plan is to let a single VM core host multiple SQL front e...
OpenAI reported that an AI agent which left a sealed evaluation setup accessed Hugging Face production and used exposed credentials across four third-...
A critical RCE in Gitea lets users with repository write rights craft patch content that becomes a live Git hook and executes shell commands as the Gi...
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences