Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 IMPERVABLOG:E4E...

Imperva Customers Protected Against CVE-2026-45247 in Mirasvit Full Page Cache Warmer for Magento_IMPERVABLOG:E4E2C1D23C9CF8EE01C3B384B9B152C9

**_TL;DR:_** _CVE-2026-45247_ _is a critical unauthenticated remote code execution (RCE) vulnerability affecting Mirasvit Full Page Cache Warmer fo...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:C03...

Real-Time Webhook Notifications: No More Lost Security Alerts_IMPERVABLOG:C0352C43EEEEF906CB937260B70AED49

Every security team knows the pain: a critical alert lands in someone’s inbox, buried under dozens of other emails, or filtered out by a spam rule....

N/A N/A IMPERVABLOG
MEDIUM 6.5 IMPERVABLOG:B3D...

Imperva Customers Protected Against CVE-2026-9082 in Drupal Core_IMPERVABLOG:B3D3F560C05210784BB760168A0136D3

**_TL;DR:_**_CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core that can be exploited by unauthenticated users against D...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:462...

Dify: When Your AI Platform Becomes the Attack Surface_IMPERVABLOG:4621FF44A630721E0269C594E0434B43

## Executive Summary We identified a couple of vulnerabilities in AI automation platform Dify resulting in cross-tenant sensitive information disc...

N/A N/A IMPERVABLOG
CRITICAL 9.2 IMPERVABLOG:CE5...

CVE-2026-42945: Imperva Customers Protected Against Critical NGINX Rewrite Module Vulnerability_IMPERVABLOG:CE57D244A6F7C1AEF8FF90CB36E2EE92

_**TL;DR:** Researchers recently disclosed CVE-2026-42945, a critical heap-based buffer overflow vulnerability affecting both NGINX Open Source and...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:FF2...

Using Bedrock with Claude Code? Your AWS Credentials Are Shared With Every Subprocess_IMPERVABLOG:FF2E6468F47434CB67407AB7F1141DBF

Many developers today are using Claude Code, with a growing portion running it through Amazon Bedrock. For enterprise teams, Bedrock offers major a...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:734...

Why AI Agents Make API Security a CISO Priority_IMPERVABLOG:734EDDB233EAE948AEB0E850B76632B1

AI agents are not a future concern. They are already changing how enterprise systems are accessed, automated, and abused. And the security implica...

N/A N/A IMPERVABLOG
HIGH 7.5 IMPERVABLOG:235...

CVE-2026-23870: Imperva Customers Protected Against Critical React Server Components DoS Vulnerability_IMPERVABLOG:235ED99A11C4D9B6C773E250355FED49

**_TL;DR:_**_A newly disclosed denial-of-service vulnerability, CVE-2026-23870, impacts React Server Components and dependent frameworks, including...

N/A N/A IMPERVABLOG
CRITICAL 10 IMPERVABLOG:C28...

Your Redis Server Looks Fine. That’s the Problem._IMPERVABLOG:C28DF37D7E21421E9A88966A4E0F7EA1

## Introduction There’s an automated attack circulating right now that breaks into unprotected Redis servers, takes over the underlying machine, a...

N/A N/A IMPERVABLOG
NONE IMPERVABLOG:B85...

API Security Operations: How to Move from Visibility to Measurable Risk Reduction_IMPERVABLOG:B85F057617B2CE7190C18B14B1EE8050

_A five-level operating model for turning API security visibility into measurable risk reduction, faster remediation, and confident digital growth ...

N/A N/A IMPERVABLOG