A vulnerability in HPE Telco Service Activator, reported on February 19, 2026, allows attackers to bypass access restrictions. The flaw is linked to improper input validation in the Undertow HTTP server core used by the…
A critical vulnerability, tracked as CVE-2025-12543, has been identified in the Undertow HTTP server, affecting Java applications like WildFly and JBoss EAP. This flaw allows attackers to hijack user sessions, leading…