CVE-2026-85695 (CVSS 9.4), and CVE-2026-85620 (CVSS 9.2) all shipped this week without default authentication. Add Microsoft’s September 3 batch – nine identity CVEs, two at CVSS 10.0 – and the ...
Attackers exploited CVE-2026-63077 to breach JetBrains Cadence, accessing a 2024 backup containing credentials and user data.
A critical vulnerability in a popular Model Context Protocol server shows that application-layer safety controls cannot ...
AI's RAG platform let attackers run arbitrary queries as PostgreSQL superuser - and the default config has auth turned off.
A severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471, has been discovered. This flaw, present ...
The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.
Threat actors are actively attempting to exploit CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in ...
Four things are necessary for application-level resilience and high availability: clustering, data replication, failover, and ...
The flaw that had gone unnoticed since 2014 could let attackers with low-privileged replication access execute code, gain ...
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
DH2i®, a leading provider of always-secure and always-on IT solutions, today announced MSSQLTips will host its webinar titled, "Simplify SQL Server HA/DR on Kubernetes." ...
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two ...