Two unpatched vulnerabilities in Claude for Chrome allow data exfiltration from Google services because the activation mechanism does not verify whether user interactions are genuine.
An unpatched denial-of-service vulnerability in Alibaba’s XQUIC library enables HTTP/3 server crashes through simple, protocol-compliant QPACK requests; Alibaba has not responded since April 2026.
An unpatched security flaw in Argo CD’s repo-server component allows network-accessible attackers to execute code with potential for complete cluster compromise.
A critical vulnerability in SimpleHelp remote management software is currently under active attack and requires immediate patching on affected systems.
The Vertex AI SDK generated predictable names for temporary Cloud Storage buckets; attackers could reserve these names and redirect model uploads, enabling code execution via manipulated pickle files.