Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2026-6477

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory_MS:CVE-2026-6477

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-6637

PostgreSQL refint allows stack buffer overflow and SQL injection_MS:CVE-2026-6637

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
MEDIUM 6.9 MS:CVE-2026-40460

NGINX ngx_quic_module vulnerability_MS:CVE-2026-40460

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-6479

PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion_MS:CVE-2026-6479

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
MEDIUM 6.3 MS:CVE-2026-40701

NGINX ngx_http_ssl_module vulnerability_MS:CVE-2026-40701

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
CRITICAL 9.2 MS:CVE-2026-42945

NGINX ngx_http_rewrite_module vulnerability_MS:CVE-2026-42945

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:05:...

N/A N/A MSCVE
MEDIUM 6.3 MS:CVE-2026-42934

NGINX ngx_http_charset_module vulnerability_MS:CVE-2026-42934

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:04:...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-42946

NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability_MS:CVE-2026-42946

{“lastseen”:”2026-05-18T09:15:24″,”description”:””,”published”:”2026-05-16T08:05:...

N/A N/A MSCVE
NONE THN:597EC3E3663...

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware_THN:597EC3E36639398344F30722E2497149

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbN7WbW1cUkMzMJl0HPvRrQQUc5MQEE3Pvrc735aG7RGwpguum4POxa4yeQjyYIyiAYBDj_Zl6Ud8esex0An...

N/A N/A THN
NONE MALWAREBYTES:FB...

A week in security (May 11 – May 17)_MALWAREBYTES:FB07D8D00C48EE0DF1CCF4A2CBA4CAD5

Last week on Malwarebytes Labs: * Attackers replaced JDownloader installer downloads with malware * Meta’s confusing new approach to chat priv...

N/A N/A MALWAREBYTES