Recent Advisories

Severity ID Title Vendor Product Date Type
NONE SCHNEIER:241805...

AI and Liability_SCHNEIER:24180570FA25CD366F3C4BC1B6F703A6

Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like "users can check for themselves...

N/A N/A SCHNEIER
NONE HACKREAD:C879C0...

Fake GTA 6 Early Access Websites Target Gamers with Malware and Crypto Scams_HACKREAD:C879C04F7479896AF809D522E0B323F4

GTA 6 scams are luring fans with fake early access, crypto payments and malware downloads. Learn why PC and Android gamers face the biggest risks o...

N/A N/A HACKREAD
HIGH 7.5 CVE-2025-61027

CVE-2025-61027_CVE-2025-61027

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61023

CVE-2025-61023_CVE-2025-61023

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-48942

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

getk2.com K2 extension for Joomla 1.0-2.26 CVE
HIGH 8.1 CVE-2026-9800

Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison_CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 4.6 CVE-2026-9799

Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass_CVE-2026-9799

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource c...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 6.5 CVE-2026-9705

Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token_CVE-2026-9705

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), coul...

Red Hat Red Hat Build of Keycloak CVE
HIGH 7.7 CVE-2026-9099

Keycloak: group-admin escalation to realm-admin_CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authentica...

Red Hat Red Hat Build of Keycloak CVE
HIGH 7.3 CVE-2026-9086

Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass_CVE-2026-9086

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to cli...

Red Hat Red Hat Build of Keycloak CVE