Multiple vulnerabilities in NGINX products compromise availability, integrity, and system security; extensive data manipulation and code execution are possible.
A rounding error in FFmpeg’s MagicYUV decoder allows arbitrary code execution through stack overflow when merely scanning video files, but affects a vulnerability patched in version 8.1.2.
CVE-2026-8461 in the FFmpeg MagicYUV decoder enables Denial-of-Service and Remote Code Execution through crafted media files in hundreds of applications; patching to version 8.1.2 is required.
A critical vulnerability in the PostgreSQL sidecar service of Splunk Enterprise (CVE-2026-20253, CVSS 9.8) is being actively exploited and requires immediate updates to version 10.2.4, 10.0.7, or 10.4.0.
CVE-2026-48907 in Joomla JCE enables unauthenticated code execution with CVSS 10.0 and is being actively exploited, while large-scale WordPress attack campaigns run parallel through manipulated plugins.
Cisco ISE contains multiple vulnerabilities that compromise critical system functions (code execution, privilege escalation, data access) and pose a high risk to network authentication.
Attackers could pre-register cloud storage buckets based on predictable naming schemes derived from project ID and region to replace uploaded models with malware before Vertex AI loaded them.