Recent Advisories

Severity ID Title Vendor Product Date Type
NONE IMPERVABLOG:1D6...

Security by Design: Why Multi-Factor Authentication Matters More Than Ever_IMPERVABLOG:1D6C593027224B312EC0C84601361ACE

In an era marked by escalating cyber threats and evolving risk landscapes, organisations face mounting pressure to strengthen their security postur...

N/A N/A IMPERVABLOG
CRITICAL 9.8 IMPERVABLOG:AF8...

Code Execution in Jupyter Notebook Exports_IMPERVABLOG:AF8A846A09089C84E360221A65091766

_After our research on_ _Cursor_ _, in the context of developer-ecosystem security, we turn our attention to the Jupyter ecosystem. We expose secur...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:D34...

Imperva Partners with TollBit to Power AI Traffic Monetization for Content Owners_IMPERVABLOG:D34A1182B67D3B2733ECB7F13AB4AADC

The surge in AI-driven traffic is transforming how websites manage their content. With AI bots and agents visiting sites at unprecedented rates (of...

N/A N/A IMPERVABLOG
CRITICAL 10 IMPERVABLOG:4C9...

Chain Reaction: Attack Campaign Activity in the Aftermath of React Server Components Vulnerability_IMPERVABLOG:4C98D6250BAC9827A8A84BB47E0F2EB3

## Introduction and Vulnerability Overview Earlier this month, Imperva published an initial advisory outlining how our customers were protected ag...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:8F1...

The Privacy Gap in API Security: Why Protecting APIs Shouldn’t Put Your Data at Risk_IMPERVABLOG:8F15A1DDF9B1DA1EDF62C2AFE9ED613A

The more critical APIs become, the more sensitive data they carry identities, payment details, health records, customer preferences, tokens, keys, ...

N/A N/A IMPERVABLOG
CRITICAL 10 IMPERVABLOG:24C...

Imperva Customers Protected Against React Server Components (RSC) Vulnerability_IMPERVABLOG:24C99ED840303E01AC4633745DA94C7E

## Overview On December 3, 2025, the React and Next.js teams disclosed a critical security vulnerability (CVSS 10.0), identified as React2Shell, a...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:82A...

’Tis the Season to Be Cyber-Wary: How Thales Protects Against Account Takeover During Peak Shopping Season_IMPERVABLOG:82AC0610CCDD753EAA4C841FB6785D90

The holiday shopping season is the busiest time of year for online retailers, and increasingly the most dangerous. As traffic surges and customers ...

N/A N/A IMPERVABLOG
CRITICAL 9.8 IMPERVABLOG:739...

CVE-2025-61757: Imperva Customers Protected Against Critical Oracle Identity Manager Authentication Bypass Leading to Remote Code Execution_IMPERVABLOG:739D0AA585D1E1F1A4FC9387FDB76EF3

At the end of October 2025, Oracle released an emergency security alert addressing CVE-2025-61757, a high-severity authentication-bypass flaw that ...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:2A5...

How Thales Protects Online Retail Sites from AI-Driven Bots during Holiday Shopping Season_IMPERVABLOG:2A574E6BE1316C051E5BB6661753A6A9

Every November and December, online retailers gear up for their biggest revenue surge of the year. But while the traffic and transactions climb, so...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:B32...

Paris, The Thinker, and why your WAF should block XSS by default_IMPERVABLOG:B32B55FF9E66EDA56644A9CDCC067F00

With Thales HQ in Paris, it felt right to detour to the Musée Rodin and stand before The Thinker, the bronze giant by Auguste Rodin whose clenched ...

N/A N/A IMPERVABLOG