An authentication bypass in PicketLink Federation lets an unauthenticated attacker forge SAML assertions and sign in to JBoss EAP applications as any user, including administrators.
A memory corruption flaw in SAP NetWeaver Application Server ABAP lets an unauthenticated attacker crash the system or disclose sensitive system information through crafted DIAG protocol traffic.
A privilege escalation flaw in cPanel & WHM’s database management lets any authenticated hosting account execute database commands with full administrative privileges, exposing every database on the server.
A code injection flaw in Gitea’s diffpatch endpoint lets a user with repository write access install a Git hook and run arbitrary shell commands as the Gitea service account.
Apache Traffic Server’s July 2026 security release patches dozens of flaws across its plugin surface, with the most severe letting unauthenticated attackers crash proxy tiers and bypass access controls.
An out-of-bounds write in Samba’s internal DNS server lets an unauthenticated attacker crash a domain controller’s DNS process with a single crafted TSIG packet.
Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.
A flaw in the chunked upload handler of WPForms Pro lets an unauthenticated attacker leave executable files on a WordPress server, opening a path to remote code execution.
A flaw in the Authentication Engine of Oracle Access Manager lets an unauthenticated attacker take over the single sign-on service that fronts an organization’s internal applications.
Oracle’s July 2026 Critical Patch Update fixes multiple flaws in WebLogic Server’s Core component, several letting an unauthenticated attacker fully take over the server over T3, IIOP, HTTP, and SOAP.