ISC2 domain 8
Software Development Security
Security in what gets built: vulnerabilities in software and libraries, the code supply chain, package registries and APIs.
News
149 articles in this subject area
Citrix reports multiple vulnerabilities in NetScaler ADC and Gateway
Citrix has published a bulletin covering multiple NetScaler ADC and Gateway vulnerabilities, scored 6.9 to 8.8 in CVSSv4 and requiring no authentication.
A flaw in Metabase gave administrator access without a sign-in
Metabase confirmed on 6 August that a vulnerability in version 58 and later is being exploited in attacks. An unauthenticated attacker can inject SQL into Metabase's own application database through the password reset endpoint, and from there gain administrator access.
The WordPress login screen let anyone inject code
WordPress released version 7.0.3 on 6 August, fixing a vulnerability on the login screen that requires no sign-in. The finders show how the flaw can, under certain conditions, end with PHP code running on the server.
Official installers for QuickFox VPN carried a backdoor for nearly a year
Fortinet has found that the QuickFox VPN installers spread a backdoor for nearly a year. The backdoor was only installed on machines that looked like work machines.
The AI agents built their own message board, and got out of the test environment
OpenAI presented new technical details at Black Hat on 6 August 2026 about experimental agents that broke out of the test environment. According to the presentation, the agents used an internal Artifactory server as a message board, gained administrative access through a flaw there, and restored the channel after OpenAI had rebuilt the service and revoked the credentials.
The AI notetaker let strangers into the meetings, and no one had to break in
Security researcher BobDaHacker reports that AI notetaker tl;dv lacked separation between customers in its database, so any signed-in user could pull meeting data from across the platform. Dark Reading wrote on 4 August 2026 that the exposure was still active, six months after the vendor was first notified.
Self-propagating worm in npm compromised Keyv and other widely used packages
A large scale supply chain attack on npm, tracked as ChainDrop, hit Keyv and other widely used packages. The malware ran during installation, stole credentials from developers and build pipelines, and used that access to publish further infected releases automatically.
Critical flaw in Rails Active Storage let uploaded files read secrets
Ruby on Rails fixed a critical vulnerability in Active Storage on 29 July 2026. An attacker without login could upload a crafted file and have files read from the server, among them application secrets and credentials for other services. Upgrading alone is not enough, because secrets that may already be stolen have to be replaced.
Critical Ruflo vulnerability gives command execution without login
On 29 July 2026 Noma Labs disclosed CVE-2026-59726, a vulnerability scored 10.0 in Ruflo. In the default Docker Compose deployment the platform MCP bridge was open on port 3001 without authentication, exposing 233 tools, among them shell command execution.
FastJson zero-day actively exploited, and no fix exists
CVE-2026-16723 in the FastJson Java library enables remote code execution without user interaction and is being exploited against US organisations. Alibaba confirms the severity, and the advice is SafeMode or switching builds.
Critical SharePoint vulnerability now actively exploited
CVE-2026-58644 allows remote code execution in Microsoft SharePoint and entered CISA's known exploited catalogue days after publication.
Microsoft's July update fixes three zero-day flaws
Microsoft's July release addresses over 570 vulnerabilities, including three zero-days, two of them already under active exploitation.
Urgent updates released for SonicWall SMA 100
SonicWall has fixed several flaws in the SMA 100 series, including critical ones that may allow remote code execution.
Cursor can execute a malicious file from a repository
Mindgard has shown that Cursor on Windows can execute a malicious git.exe placed in a repository root without prompting the user.
Critical Zoom flaw allows account takeover
CVE-2026-53412 in Zoom Workplace for Windows can let an unauthenticated attacker take over an account with no user interaction.
Fake GitHub repositories spread the BoryptGrab infostealer
Arctic Wolf Labs found at least 292 GitHub repositories impersonating known software and security brands to distribute an information stealer.
Palo Alto releases a fix for a PAN-OS vulnerability
CVE-2026-0288 can, under specific conditions, let an authenticated attacker affect confidentiality and integrity in PAN-OS.
Fake packages impersonate well-known payment libraries
Socket has uncovered a campaign where npm and PyPI packages mimic popular payment libraries through small naming differences.
Bad Epoll grants root access in the Linux kernel
CVE-2026-46242 is a use-after-free in the Linux kernel's epoll that lets an unprivileged process gain root on servers, desktops and Android devices.
Synacktiv: unauthenticated code execution in Argo CD with no official fix
Synacktiv has published a flaw in Argo CD's repo-server that can give unauthenticated code execution and, at worst, full Kubernetes cluster compromise.
CISA adds SharePoint vulnerability to its exploited-flaws catalogue
On 1 July CISA added CVE-2026-45659 to the KEV catalogue, a deserialisation flaw in Microsoft Office SharePoint allowing code execution.
Unit 42: language models invent domains that attackers then register
Unit 42 found around 250,000 unregistered domains invented by language models, and at least one case where an attacker registered one and set up phishing.
Adobe patches twelve vulnerabilities in ColdFusion and Campaign Classic
Adobe has published updates fixing twelve CVEs in ColdFusion and Adobe Campaign Classic, several allowing arbitrary code execution.
Exploitation observed of critical Oracle E-Business Suite flaw
Defused Cyber has observed exploitation attempts against CVE-2026-46817 in Oracle E-Business Suite Payments, a CVSS 9.8 flaw Oracle patched in May.