Unpatched LMCache flaw allows unauthenticated code execution on LLM cache servers
JFrog disclosed CVE-2026-105192, a 9.8-rated flaw in LMCache's multiprocess mode that lets a single network message run code. No fixed version is available yet.
The latest cybersecurity news in Vulnerabilities.
JFrog disclosed CVE-2026-105192, a 9.8-rated flaw in LMCache's multiprocess mode that lets a single network message run code. No fixed version is available yet.
SonicWall has released hotfixes for CVE-2026-102255, an unauthenticated server-side request forgery flaw in SMA 1000 appliances that could let attackers reach internal functions.
Researchers earned $419,500 on the first day of Pwn2Own Ireland 2026 in Dublin, with 15 successful attempts against phones, printers, smart home devices and AI tools.
Patchstack says a single campaign is abusing stored XSS bugs in Ninja Forms and WPC Product Bundles to create admin accounts, a magic login link and a file manager backdoor.
LibreOffice 26.2.5 and 26.8.0 close a flaw that lets a crafted spreadsheet load a remote Java database driver and execute code silently. Apache OpenOffice has no fix yet.
Perforce has fixed six flaws in P4 Search, including a maximum-severity authentication bypass that hands unauthenticated attackers the highest privilege on the service.
Atlassian says CVE-2026-21589 lets unauthenticated attackers read files from the web application root of Jira, Confluence, Bitbucket and five other self-hosted products. All versions are affected.
Citrix released emergency builds for CVE-2026-88779, a memory overflow in NetScaler SAML deployments that attackers are using to knock appliances offline.
Dell patched five flaws in its System Update deployment tool, led by a CVSS 9.6 path traversal bug that can let a remote, unauthenticated attacker run code as root. Version 2.3.0.0 fixes all of them.
CVE-2026-61500 lets an unauthenticated attacker predict HFS session signing keys and take over the admin account. Exploitation was seen on October 1.
A working exploit generator and full write-up are now public for CVE-2026-43682, a kernel heap overflow Apple fixed in July. Mounting a crafted disk image is enough to corrupt kernel memory.
Kiteworks fixed CVE-2026-54154, a CVSS 10 flaw chain in its Email Protection Gateway that could let unauthenticated attackers run code as root. Version 9.4.1 fixes it.