Atlassian Bamboo, Bitbucket, Confluence, Crucible, Fisheye and Jira are affected by multiple vulnerabilities enabling code execution and security bypasses.
Six widely used AI coding assistants can be tricked via malicious repositories containing hidden symlinks to manipulate files outside their sandbox, with confirmation dialogs masking the actual action.
Two sandbox-escape vulnerabilities (CVE-2026-50548, CVE-2026-50549, CVSS 9.8) in Cursor enable remote code execution on the operating system via manipulated prompts — patch available since April.
Red Hat JBoss Enterprise Application Platform contains multiple exploitable vulnerabilities that enable code execution, XSS, denial of service, and security bypass.