Advertisement
MikroTik RouterOS Unauthenticated SSH Exploit: Critical Advisory
Attackers are exploiting a critical vulnerability in MikroTik RouterOS via internet-exposed SSH to gain full administrative control without authentication.
NVIDIA NemoClaw Weakness Allows AI Model Poisoning via Ollama
Oasis Security uncovered a weakness in NVIDIA NemoClaw allowing unauthenticated AI model poisoning through a malicious webpage exploiting Ollama.
GitLab GraphQL Flaw CVE-2026-19478: Unauthenticated Project Deletion
GitLab addresses a critical GraphQL flaw (CVE-2026-19478) allowing unauthenticated attackers to delete public projects and user data on self-managed CE/EE instances.
Metabase Zero-Day Exploited: Unauthenticated Admin Access
Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.
MongoBleed: Unauthenticated Credential Theft via Server Memory
Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…
ServiceNow Data Exposure via Unauthenticated API Flaw
ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.
Advertisement
Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws
Oracle's April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.