🚨 Critical Ollama Vulnerability: CVE-2026-103663 A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure. #SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement
CVE list
by @udontknow.us
[unofficial] Collect posts with a reference to CVEs
Ransomware Actors Weaponize Palo Alto GlobalProtect Authentication Bypass for Stealthy VPN Access Palo Alto GlobalProtect CVE-2026-0257 is being exploited by Qilin and Settra ransomware actors. Check affected PAN-OS… https://thecybersecguru.com/news/cve-2026-0257-globalprotect-vpn-ransomware/
Attackers bypass GlobalProtect VPN using CVE-2026-0257—patch fast. #CVE2026-0257 #GlobalProtect #VPN #CyberSecurity #PaloAlto #Ransomware https://thedailytechfeed.com/ransomware-gangs-exploiting-palo-alto-globalprotect-bypass-to-infiltrate-vpn-access/
[ICYMI] Satu celah keamanan bisa membuka pintu lebar-lebar bagi malware canggih, seperti pada kasus CVE-2025-48595. Penyerang bisa menarget jurnalis dan aktivis. https://melekmedia.org/artikel/malware-ini-diam-diam-bisa-ambil-alih-android/
CVE-2026-107845 lets unauthenticated Contao Comments Bundle visitors inject JavaScript into the back end. Opening the Comments module executes it in the user's session; the back end sends no CSP.
New on CapturedTech: OpenSSL 4.0.3 DTLS Heap Memory Leak — the CVE-2026-84782 fix, explained. What broke, how the patch fixes it, and how to update safely. capturedtech.com/Home/Post/8898 #OpenSSL #Cybersecurity #DTLS
🟠 CVE-2026-78530 - High (7.7) Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions. https://www.thehackerwire.com/vulnerability/CVE-2026-78530/ #infosec #cybersecurity #CVE #vulnerability #security #patchstack
🔴 CVE-2026-78529 - Critical (9.8) Unauthenticated PHP Object Injection in Alliance <= 3.11 versions. https://www.thehackerwire.com/vulnerability/CVE-2026-78529/ #infosec #cybersecurity #CVE #vulnerability #security #patchstack