Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian has released emergency fixes for a critical arbitrary file access vulnerability that affects eight of its products — including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589 with a CVSS score of 9.3, the flaw allows unauthenticated attackers to retrieve specific files from an application’s web root if they can guess the exact path and filename. While the bug does

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000

Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000

Vercel has publicly acknowledged a reported KVM zero-day that a security researcher says enables a full guest-to-host virtual machine escape, and the company has granted the finder its top bounty of $50,000. The disclosure raised immediate concern because Vercel uses isolated microVMs as the primary sandbox boundary for untrusted workloads and AI agents, and a successful escape to host root

Critical Dell Container Storage Flaws Expose Admin Controls — Immediate Upgrades Required

Critical Dell Container Storage Flaws Expose Admin Controls — Immediate Upgrades Required

Dell’s Container Storage Modules (CSM) were found to contain multiple critical vulnerabilities that can allow unauthenticated remote attackers to gain full administrative control of affected storage environments. The most severe issues — two CVSS 10.0 flaws — permit attackers to bypass authentication and escalate to administrator privileges, while other high-severity flaws enable privilege escalation inside Kubernetes clusters or token forgery.

Critical GitLab AI Gateway Flaw: What Administrators Need to Do Now

Critical GitLab AI Gateway Flaw: What Administrators Need to Do Now

GitLab has pushed an urgent set of security updates after disclosing a critical vulnerability in its AI Gateway that could allow authenticated users to run arbitrary commands on the gateway. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw affects self-hosted AI Gateway deployments that support GitLab Duo AI features. While GitLab’s hosted gateways have already been patched, organizations running

Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know

Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know

Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in NetScaler appliances, but some organizations report that the patched appliances are repeatedly rebooting. What began as a rapid mitigation effort to stop remote command execution and DTLS-related attacks has morphed into an availability problem for some deployments—raising the difficult question defenders must balance: is this an operational outage

Debian Patches 1,313 Kernel Flaws: What Administrators Need to Know

Debian Patches 1,313 Kernel Flaws: What Administrators Need to Know

Debian has just released a major kernel security update that aggregates fixes for 1,313 CVE entries, a headline figure that has drawn attention across the Linux community. The update — published as DSA-6528-1 and delivered for the Trixie stable release as Linux source package 6.12.111-1 — addresses a range of vulnerabilities that could, in different contexts, lead to privilege escalation,