IBM WebSphere Application Server and Liberty contain multiple vulnerabilities that enable arbitrary code execution with server privileges, data disclosure, and privilege escalation.
CISA expands SBOM minimum elements with new data fields such as hash values, licenses, and author signatures to enable organizations better software supply chain transparency.
Unauthenticated attackers can exploit multiple vulnerabilities in the Terraform MCP Server to bypass access control mechanisms, disclose sensitive information, and manipulate data.
SAP released patches in July 2026 against vulnerabilities that enable arbitrary code execution, SQL injection, cross-site scripting, file manipulation, information disclosure, and circumvention of security controls.
Azure Automation enables cross-tenant identity takeovers through default configuration; Microsoft also has three critical infrastructure security vulnerabilities.