Cross-Site Scripting (xss) is a mitre_attack tracked across 14 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 27, 2025; most recent activity July 18, 2026.
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
A critical vulnerability, CVE-2026-22752, has been identified in Spring Authorization Server, affecting versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. The flaw allows attackers with a…
An AI analysis by Aisle revealed 38 security vulnerabilities in OpenEMR, a widely used electronic health record platform. These vulnerabilities, which include critical SQL injection flaws, could have allowed attackers…
SAP has released security updates addressing 15 vulnerabilities, including four critical ones affecting SAP NetWeaver and SAP Commerce Cloud. The vulnerabilities include CVE-2026-44748, allowing authenticated attackers…
On May 12, 2026, SAP released security updates for 15 vulnerabilities, including two critical flaws in Commerce Cloud and S/4HANA. The first critical vulnerability (CVE-2026-34263) allows unauthenticated attackers to…
A large-scale analysis revealed that 5,832 out of 9,695 Model Context Protocol (MCP) servers are vulnerable to critical security flaws, including arbitrary file access, command injection, and SQL injection. These…
Recent analyses of vibe-coded applications reveal common security vulnerabilities due to the nature of AI coding agents. Tenzai's research identified 69 vulnerabilities across five popular coding agents, focusing on…
The San Francisco Secure Software and AppSec Summit 2026 gathered over 150 security professionals to address emerging threats in application security, particularly those posed by AI-driven technologies. Key discussions…
Ethical hacking, or penetration testing, is a crucial practice for identifying vulnerabilities in computer systems before malicious hackers can exploit them. In 2026, ethical hackers utilize tools like Nmap, Metasploit,…