Vulnerability-disclosure is a topic tracked in our intelligence system with 5 linked articles.
Public exploit details for a pre-auth RCE in unpatched vBulletin; affects versions up to 6.2.1 and 6.1.6, executable via unauthenticated PHP eval() calls on unpatched servers; exploit details disclosed on July 27.
OAuth parameter injection vulnerability in auth0/nextjs-auth0, plus AI-generated commit attribution and a controversial disclosure stance, highlighting governance and compliance risk for vendor security handling.
Curl reportedly won't accept vulnerability reports during July 2026.
Microsoft threatens criminal action against Nightmare Eclipse over a zero-day disclosure and has disabled the researcher’s accounts, highlighting tensions around coordinated vulnerability disclosure.
Security research finds Microsoft Copilot Cowork vulnerable to indirect prompt injection, enabling exfiltration of files via pre-authenticated download links without user approval.
Security researcher discloses React2Shell RCE in React/Flight (CVE-2025-55182); Meta patched within ~17 hours; millions of sites potentially affected.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.