<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Freedom Coder</title>
    <description>The latest articles on DEV Community by Freedom Coder (@freedom-coder).</description>
    <link>https://dev.to/freedom-coder</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3057520%2F80e0c6d9-1160-4c3a-9af3-cdf5c163c85b.png</url>
      <title>DEV Community: Freedom Coder</title>
      <link>https://dev.to/freedom-coder</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/freedom-coder"/>
    <language>en</language>
    <item>
      <title>CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 29 May 2026 22:01:12 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-0257-palo-alto-networks-pan-os-authentication-bypass-vulnerability-3pk1</link>
      <guid>https://dev.to/freedom-coder/cve-2026-0257-palo-alto-networks-pan-os-authentication-bypass-vulnerability-3pk1</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-0257&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Palo Alto Networks PAN-OS Authentication Bypass Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Palo Alto Networks&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;PAN-OS&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-29&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-01&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://security.paloaltonetworks.com/CVE-2026-0257" rel="noopener noreferrer"&gt;https://security.paloaltonetworks.com/CVE-2026-0257&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0257" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-0257&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/" rel="noopener noreferrer"&gt;Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation/" rel="noopener noreferrer"&gt;PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>paloaltonetworks</category>
      <category>panos</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-8398: Daemon Tools Lite Embedded Malicious Code Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 27 May 2026 22:07:45 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-8398-daemon-tools-lite-embedded-malicious-code-vulnerability-333a</link>
      <guid>https://dev.to/freedom-coder/cve-2026-8398-daemon-tools-lite-embedded-malicious-code-vulnerability-333a</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-8398&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Daemon Tools Lite Embedded Malicious Code Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Daemon&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Daemon Tools Lite&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-27&lt;/li&gt;
&lt;li&gt;Due Date: 2026-05-30&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://blog.daemon-tools.cc/post/security-incident" rel="noopener noreferrer"&gt;https://blog.daemon-tools.cc/post/security-incident&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8398" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-8398&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>daemon</category>
      <category>daemontoolslite</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-45321: TanStack Unspecified Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 27 May 2026 22:04:24 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-45321-tanstack-unspecified-vulnerability-l2m</link>
      <guid>https://dev.to/freedom-coder/cve-2026-45321-tanstack-unspecified-vulnerability-l2m</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-45321&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;TanStack Unspecified Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;TanStack&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;TanStack&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-27&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-10&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: &lt;a href="https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx" rel="noopener noreferrer"&gt;https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45321" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-45321&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>tanstack</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 27 May 2026 22:01:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-48027-nx-console-embedded-malicious-code-vulnerability-lag</link>
      <guid>https://dev.to/freedom-coder/cve-2026-48027-nx-console-embedded-malicious-code-vulnerability-lag</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-48027&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Nx Console Embedded Malicious Code Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Nx&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Nx Console&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-27&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-10&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: &lt;a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w" rel="noopener noreferrer"&gt;https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48027" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-48027&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>nx</category>
      <category>nxconsole</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Tue, 26 May 2026 19:01:05 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-vulnerability-255e</link>
      <guid>https://dev.to/freedom-coder/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-vulnerability-255e</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-48172&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;LiteSpeed cPanel Plugin Privilege Escalation Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;LiteSpeed&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;cPanel Plugin&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-26&lt;/li&gt;
&lt;li&gt;Due Date: 2026-05-29&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/" rel="noopener noreferrer"&gt;https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48172" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-48172&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-gives-feds-4-days-to-patch-actively-exploited-cpanel-plugin-flaw/" rel="noopener noreferrer"&gt;CISA gives feds 4 days to patch actively exploited cPanel plugin flaw&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>litespeed</category>
      <category>cpanelplugin</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-9082: Drupal Core SQL Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 22 May 2026 22:01:03 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-9082-drupal-core-sql-injection-vulnerability-g96</link>
      <guid>https://dev.to/freedom-coder/cve-2026-9082-drupal-core-sql-injection-vulnerability-g96</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-9082&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Drupal Core SQL Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Drupal&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Core&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-22&lt;/li&gt;
&lt;li&gt;Due Date: 2026-05-27&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.drupal.org/sa-core-2026-004" rel="noopener noreferrer"&gt;https://www.drupal.org/sa-core-2026-004&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9082" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-9082&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/" rel="noopener noreferrer"&gt;CISA orders feds to patch actively exploited Drupal vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev/" rel="noopener noreferrer"&gt;Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>drupal</category>
      <category>core</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2010-5330: Ubiquiti AirOS Command Injection Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 22 May 2026 16:30:07 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2010-5330-ubiquiti-airos-command-injection-vulnerability-35fb</link>
      <guid>https://dev.to/freedom-coder/cve-2010-5330-ubiquiti-airos-command-injection-vulnerability-35fb</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2010-5330&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Ubiquiti AirOS Command Injection Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Ubiquiti&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;AirOS&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2022-04-15&lt;/li&gt;
&lt;li&gt;Due Date: 2022-05-06&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply updates per vendor instructions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2010-5330" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2010-5330&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/" rel="noopener noreferrer"&gt;Ubiquiti patches three max severity UniFi OS vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ubiquiti</category>
      <category>airos</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 22 May 2026 01:06:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-34926-trend-micro-apex-one-on-premise-directory-traversal-vulnerability-2pgd</link>
      <guid>https://dev.to/freedom-coder/cve-2026-34926-trend-micro-apex-one-on-premise-directory-traversal-vulnerability-2pgd</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-34926&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Trend Micro&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Apex One&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-21&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-04&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://success.trendmicro.com/en-US/solution/KA-0023430" rel="noopener noreferrer"&gt;https://success.trendmicro.com/en-US/solution/KA-0023430&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34926" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-34926&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/trend-micro-warns-of-apex-one-zero-day-exploited-in-the-wild/" rel="noopener noreferrer"&gt;Trend Micro warns of Apex One zero-day exploited in the wild&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev/" rel="noopener noreferrer"&gt;CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>trendmicro</category>
      <category>apexone</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2025-34291: Langflow Origin Validation Error Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Fri, 22 May 2026 01:01:03 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2025-34291-langflow-origin-validation-error-vulnerability-361g</link>
      <guid>https://dev.to/freedom-coder/cve-2025-34291-langflow-origin-validation-error-vulnerability-361g</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2025-34291&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Langflow Origin Validation Error Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Langflow&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Langflow&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-21&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-04&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: &lt;a href="https://github.com/langflow-ai/langflow" rel="noopener noreferrer"&gt;https://github.com/langflow-ai/langflow&lt;/a&gt; ; &lt;a href="https://github.com/langflow-ai/langflow/releases/tag/v1.9.3" rel="noopener noreferrer"&gt;https://github.com/langflow-ai/langflow/releases/tag/v1.9.3&lt;/a&gt;; &lt;a href="https://github.com/langflow-ai/langflow/issues/11465#event-25774545848" rel="noopener noreferrer"&gt;https://github.com/langflow-ai/langflow/issues/11465#event-25774545848&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34291" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2025-34291&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev/" rel="noopener noreferrer"&gt;CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>langflow</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 20 May 2026 19:09:57 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-45498-microsoft-defender-denial-of-service-vulnerability-8de</link>
      <guid>https://dev.to/freedom-coder/cve-2026-45498-microsoft-defender-denial-of-service-vulnerability-8de</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-45498&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Microsoft Defender Denial of Service Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Microsoft&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Defender&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-20&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-03&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Microsoft Defender contains an unspecified vulnerability that allows for denial of service.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498" rel="noopener noreferrer"&gt;https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45498&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45498" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-45498&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-slams-public-zero-day-disclosures-amid-github-researcher-account-removal/" rel="noopener noreferrer"&gt;Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/" rel="noopener noreferrer"&gt;Microsoft warns of new Defender zero-days exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-warns-of-two-actively-exploited-defender-vulnerabilities/" rel="noopener noreferrer"&gt;Microsoft Warns of Two Actively Exploited Defender Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-defender-vulnerabilities-exploited-in-the-wild-cve-2026-41091-cve-2026-45498/" rel="noopener noreferrer"&gt;Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>microsoft</category>
      <category>defender</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2026-41091: Microsoft Defender Link Following Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 20 May 2026 19:08:30 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2026-41091-microsoft-defender-link-following-vulnerability-5b0p</link>
      <guid>https://dev.to/freedom-coder/cve-2026-41091-microsoft-defender-link-following-vulnerability-5b0p</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2026-41091&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Microsoft Defender Link Following Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Microsoft&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Defender&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-20&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-03&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091" rel="noopener noreferrer"&gt;https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41091" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-41091&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-slams-public-zero-day-disclosures-amid-github-researcher-account-removal/" rel="noopener noreferrer"&gt;Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/" rel="noopener noreferrer"&gt;Microsoft warns of new Defender zero-days exploited in attacks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-warns-of-two-actively-exploited-defender-vulnerabilities/" rel="noopener noreferrer"&gt;Microsoft Warns of Two Actively Exploited Defender Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-defender-vulnerabilities-exploited-in-the-wild-cve-2026-41091-cve-2026-45498/" rel="noopener noreferrer"&gt;Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>microsoft</category>
      <category>defender</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>CVE-2010-0806: Microsoft Internet Explorer Use-After-Free Vulnerability</title>
      <dc:creator>Freedom Coder</dc:creator>
      <pubDate>Wed, 20 May 2026 19:07:04 +0000</pubDate>
      <link>https://dev.to/freedom-coder/cve-2010-0806-microsoft-internet-explorer-use-after-free-vulnerability-1bnj</link>
      <guid>https://dev.to/freedom-coder/cve-2010-0806-microsoft-internet-explorer-use-after-free-vulnerability-1bnj</guid>
      <description>&lt;h3&gt;
  
  
  CVE ID
&lt;/h3&gt;

&lt;p&gt;CVE-2010-0806&lt;/p&gt;

&lt;h3&gt;
  
  
  Vulnerability Name
&lt;/h3&gt;

&lt;p&gt;Microsoft Internet Explorer Use-After-Free Vulnerability&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Project: &lt;strong&gt;Microsoft&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Product: &lt;strong&gt;Internet Explorer&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Date
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Date Added: 2026-05-20&lt;/li&gt;
&lt;li&gt;Due Date: 2026-06-03&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Description
&lt;/h3&gt;

&lt;p&gt;Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.&lt;/p&gt;

&lt;h3&gt;
  
  
  Known To Be Used in Ransomware Campaigns?
&lt;/h3&gt;

&lt;p&gt;Unknown&lt;/p&gt;

&lt;h3&gt;
  
  
  Action
&lt;/h3&gt;

&lt;p&gt;Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Additional Notes
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/981374&lt;/a&gt; ; &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0806" rel="noopener noreferrer"&gt;https://nvd.nist.gov/vuln/detail/CVE-2010-0806&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Related Security News
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.scyscan.com/news/microsoft-warns-of-two-actively-exploited-defender-vulnerabilities/" rel="noopener noreferrer"&gt;Microsoft Warns of Two Actively Exploited Defender Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  More CVEs Info
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://www.scyscan.com/cves/" rel="noopener noreferrer"&gt;Common Vulnerabilities &amp;amp; Exposures (CVE) List&lt;/a&gt;&lt;/p&gt;

</description>
      <category>microsoft</category>
      <category>internetexplorer</category>
      <category>cybersecurity</category>
      <category>vulnerability</category>
    </item>
  </channel>
</rss>
