An unpatched Argo CD vulnerability demonstrates that GitOps platforms must protect internal cluster access with the same security rigor as external exposure, because any compromised pod can directly execute code and manipulate deployments.
Logic errors in Cursor’s sandbox isolation enable prompt-injection attackers to achieve remote code execution without user interaction; patches have been available since April.
An unpatched security flaw in Argo CD’s repo-server component allows network-accessible attackers to execute code with potential for complete cluster compromise.
A critical pre-authentication RCE vulnerability (CVE-2026-8037, CVSS 9.8) in Progress Kemp LoadMaster allows root commands via the API; a patch is available.
The critical deserialization vulnerability CVE-2026-12569 in PTC Windchill PDMLink is being actively exploited; attackers are installing web shells and targeting sensitive design and engineering data in defense, aerospace, and automotive sectors.
PostgreSQL contains multiple critical vulnerabilities allowing remote code execution and data manipulation; BSI classifies the threat level as elevated.