Vendor Security News

Vendor security advisories, disclosures and statements from software and hardware makers about issues in their own products.

When a vendor issues its own security advisory — acknowledging a flaw, describing its impact, or announcing a fix — it is usually the most authoritative account of what actually happened. This feed tracks vendor-issued advisories and statements across the ecosystem, from routine security bulletins to public responses following in-the-wild exploitation. It is the direct-from-the-source counterpart to third-party CVE and exploit reporting.

Recent Vendor items

CVE-2026-73846CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-s…
@cveNotify · Aug 14, 2026
CVE-2026-73845CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaSer…
@cveNotify · Aug 14, 2026
CVE-2026-73844CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller inste…
@cveNotify · Aug 14, 2026
CVE-2026-49989CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs uncondi…
@cveNotify · Aug 14, 2026
CVE-2026-49986The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by…
@cveNotify · Aug 14, 2026
CVE-2026-49826Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse…
@cveNotify · Aug 14, 2026
CVE-2026-47766crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If a…
@cveNotify · Aug 14, 2026
CVE-2026-47192kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to vali…
@cveNotify · Aug 14, 2026
CVE-2026-47191kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to…
@cveNotify · Aug 14, 2026
CVE-2026-46439compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `tre…
@cveNotify · Aug 14, 2026
CVE-2026-46380compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to r…
@cveNotify · Aug 14, 2026
CVE-2026-19845A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing…
@cveNotify · Aug 14, 2026
CVE-2026-19844A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing…
@cveNotify · Aug 14, 2026
CVE-2026-19839A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in…
@cveNotify · Aug 14, 2026
CVE-2026-19838A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting E…
@cveNotify · Aug 14, 2026
CVE-2026-19628A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution o…
@cveNotify · Aug 14, 2026
CVE-2026-19626A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying…
@cveNotify · Aug 14, 2026
CVE-2026-70338Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-70130Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-66807Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-63515Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-53970ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substit…
@cveNotify · Aug 14, 2026
CVE-2026-19884In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications b…
@cveNotify · Aug 14, 2026
CVE-2026-19837A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation…
@cveNotify · Aug 14, 2026
CVE-2026-19836A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Custome…
@cveNotify · Aug 14, 2026
CVE-2026-19835A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulati…
@cveNotify · Aug 14, 2026
CVE-2026-19834A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonatio…
@cveNotify · Aug 14, 2026
CVE-2026-70315Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-70314Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.🎖@cveNotify
@cveNotify · Aug 14, 2026
CVE-2026-62908Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.🎖@cveNoti…
@cveNotify · Aug 14, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.