Linuxsecurity Critical XML Entity Vulnerabilities Fixed in Fedora 43 and 44 Updates
Article Content
- •Fedora 43 and 44 released critical updates for XMLStarlet on June 11, 2026.
- •The updates fix XML External Entity (XXE) vulnerabilities that could expose sensitive data.
- •Users are urged to apply the updates immediately using the 'dnf' update program.
On June 11, 2026, Fedora released updates for XMLStarlet in versions 43 and 44 to address XML External Entity (XXE) vulnerabilities. These vulnerabilities could allow attackers to exploit XML parsing features, potentially leading to unauthorized access to sensitive data. The updates were made available by Vitezslav Crhonek and are crucial for users of Fedora 43 and 44. Users are advised to upgrade using the 'dnf' update program. The vulnerabilities were identified in version 1.6.1-30 of XMLStarlet, which is a command-line toolkit for XML processing. The updates are essential for maintaining security and preventing potential exploitation. No specific CVEs were mentioned in the articles, but the nature of the vulnerabilities suggests a significant risk if left unpatched.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…