qesportal.sk Critical Vulnerability in Web Signer Affects Multiple OS Versions
Article Content
Browse articles
- •A critical vulnerability in Web Signer affects versions 2.0.3 to 2.5.3.
- •The flaw was identified by Marek Alakš from Binary House and patched in version 2.5.5.
- •Users are urged to update immediately to avoid potential exploitation.
A serious vulnerability has been identified in older versions of the Web Signer application (2.0.3 - 2.5.3) for Windows, macOS, and Linux. The flaw was discovered by Marek Alakš from Binary House and has been patched in version 2.5.5. Users are advised to update their applications immediately, as the application will prompt for an update shortly. Manual updates can also be initiated by right-clicking the yellow icon in the system tray. The vulnerability poses risks to all users of the affected versions, necessitating swift action to mitigate potential exploitation. The updated installation packages are available on the vendor's website.
Ask AI about this cluster
Answers cite the sources they use
Updated 111d ago How this analysis works
Timeline
2026-06-02
Vulnerability identified in Web Signer
Marek Alakš from Binary House discovered a serious vulnerability in Web Signer versions 2.0.3 - 2.5.3, affecting multiple operating systems.
qesportal.sk2026-06-02
Patch released for Web Signer
Version 2.5.5 of Web Signer was released to address the identified vulnerability, with users advised to update immediately.
www.disig.skMore articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…