vulnerability Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory A critical vulnerability (CVE-2026-59726) in Ruflo, an AI agent orchestration platform, allows unauthenticated remote code execution. Attackers can steal LLM API keys, harvest user conversations, and poison AI memory, le… The Hacker News · Jul 29, 2026 Critical CVE-2026-59726airemote code executionapi key theft
vulnerability Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape Broadcom has released security updates to address three critical vulnerabilities in VMware products, including a virtual machine escape. These flaws allow for authentication bypass, code execution, and potentially unauth… The Hacker News · Jul 29, 2026 High CVE-2026-59309CVE-2026-59310CVE-2026-47876vulnerabilitypatchsecurity
vulnerability Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms A critical vulnerability (CVE-2026-59726) in the Ruflo AI agent platform allows unauthenticated attackers to gain full remote code execution, access provider API keys, and even tamper with the AI's memory, potentially un… Dark Reading · Jul 29, 2026 Critical CVE-2026-59726aimemory corruptionremote code execution
vulnerability Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Researchers at Nebula Security discovered a vulnerability in Firefox's JIT compiler that allows a single malicious webpage visit to compromise the browser, including Tor Browser. This vulnerability, CVE-2026-10702, can b… The Hacker News · Jul 29, 2026 High CVE-2026-10702CVE-2026-43499jitsifirefoxexploit
vulnerability Critical VM Escape Vulnerability Patched in VMware ESXi VMware has released patches to address several critical vulnerabilities in its ESXi, vCenter, Workstation, and Fusion products. These flaws could allow attackers to execute code on the host, bypass authentication, or cau… SecurityWeek · Jul 29, 2026 Critical CVE-2026-47876CVE-2026-59309CVE-2026-59310vulnerabilitypatchsecurity
vulnerability Long-Lived Vulnerability in Microsoft Secure Boot A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsi… Schneier on Security · Jul 29, 2026 High firmwareshimuefi
vulnerability Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass A critical security flaw in Check Point's SmartConsole allows unauthenticated attackers to gain full administrative privileges, and a proof-of-concept has been released. This vulnerability has been actively exploited in… The Hacker News · Jul 29, 2026 Critical CVE-2026-16232authenticationsmartconsolecheck point
vulnerability New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands A critical remote code execution (RCE) vulnerability in Gitea allows a user with repository write access to plant a Git hook and execute shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026… The Hacker News · Jul 29, 2026 High CVE-2026-60004rcegitvulnerability
vulnerability Apple Patches Everything (July 2026), (Wed, Jul 29th) Apple released a substantial security update addressing 187 vulnerabilities across its macOS, iOS, and Safari operating systems. The update focuses on patching a range of issues, including DoS attacks, privilege escalati… SANS Internet Storm Center · Jul 29, 2026 Medium CVE-2026-28849CVE-2026-28900CVE-2026-28914macosiossafari
vulnerability Multiples vulnérabilités dans Xen (29 juillet 2026) Multiple vulnerabilities have been discovered in Xen virtualization software. These vulnerabilities allow for potential data compromise, denial of service, and privilege escalation. The affected Xen versions are all with… CERT-FR · Jul 29, 2026 High CVE-2026-42492CVE-2026-42493CVE-2026-42494xenvulnerabilityhypervisor
vulnerability Vulnérabilité dans Apache Tomcat (29 juillet 2026) A critical vulnerability has been identified in Apache Tomcat, allowing attackers to cause a denial-of-service attack. This affects older versions of the web server, requiring immediate patching to prevent exploitation. CERT-FR · Jul 29, 2026 Critical CVE-2026-66299apachetomcatvulnerability
vulnerability Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing an attacker to cause data integrity issues and a security problem not specified by the vendor. These vulnerabilities are part of a lar… CERT-FR · Jul 29, 2026 High CVE-2026-62828CVE-2026-13282CVE-2026-13283vulnerabilitysecuritymicrosoft
vulnerability Multiples vulnérabilités dans Citrix XenServer (29 juillet 2026) Multiple vulnerabilities have been discovered in Citrix XenServer, allowing for remote code execution and denial of service attacks. These vulnerabilities exist in versions 8.4 and 9 without the latest security patch. Ci… CERT-FR · Jul 29, 2026 High CVE-2026-42492CVE-2026-62428CVE-2026-62431xencitrixvulnerability
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
vulnerability Click to pray expose les données de plus de 700 000 fidèles A vulnerability in the Click to Pray application, used by the Vatican’s prayer network, has exposed the personal data of over 719,517 users. Researcher BobDaHacker reported the issue six months prior, but no response was… ZATAZ · Jul 28, 2026 High UNidorphishingdata breach
vulnerability Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe Apple has released security updates addressing a significant number of vulnerabilities across its iOS, macOS, Safari, watchOS, tvOS, and visionOS operating systems. These patches address a wide range of issues, including… SecurityWeek · Jul 28, 2026 High CVE-2026-43810securitypatchvulnerabilities
vulnerability Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root OpenWrt has released version 24.10.8 to address a critical vulnerability (CVE-2026-53921) in its DHCPv6 stack, allowing unauthenticated attackers to execute code as root on devices running the firmware. The vulnerability… The Hacker News · Jul 28, 2026 High CVE-2026-53921CVE-2026-62948CVE-2026-62947dhcpv6stack-overflowluci
vulnerability Siemens Mendix Runtime A gap in Siemens Mendix Runtime documentation regarding access rules for the System.User entity has been identified, potentially leading developers to apply overly permissive access rules, exposing sensitive user data an… CISA Advisories · Jul 28, 2026 Critical CVE-2026-7891mendixaccess-controlindustrial-control-systems
vulnerability ABB KNX Update Tool ABB has identified a vulnerability in its KNX Update Tool, affecting legacy KNX devices due to a lack of security features. The vulnerability allows an attacker with physical access to the KNX bus to render the device un… CISA Advisories · Jul 28, 2026 High CVE-2026-12705
vulnerability MikroTik RouterOS and Cloud Hosted Router A critical vulnerability (CVE-2026-16347) exists in MikroTik RouterOS and Cloud Hosted Router, allowing attackers to rapidly guess passwords and gain unauthorized access by repeatedly attempting logins. No fix is current… CISA Advisories · Jul 28, 2026 Critical CVE-2026-16347vulnerabilitypassword-crackingapi