Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw

Atlassian has released emergency fixes for a critical arbitrary file access vulnerability that affects eight of its products — including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589 with a CVSS score of 9.3, the flaw allows unauthenticated attackers to retrieve specific files from an application’s web root if they can guess the exact path and filename. While the bug does

Critical GitLab AI Gateway Flaw: What Administrators Need to Do Now

Critical GitLab AI Gateway Flaw: What Administrators Need to Do Now

GitLab has pushed an urgent set of security updates after disclosing a critical vulnerability in its AI Gateway that could allow authenticated users to run arbitrary commands on the gateway. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw affects self-hosted AI Gateway deployments that support GitLab Duo AI features. While GitLab’s hosted gateways have already been patched, organizations running

Firefox 149 Ships: Patches for 37 Vulnerabilities, Including Multiple Sandbox Escapes

Firefox 149 Ships: Patches for 37 Vulnerabilities, Including Multiple Sandbox Escapes

Mozilla released Firefox 149 on March 24, 2026, in one of the browser’s largest security updates in recent memory. The release fixes 37 vulnerabilities across memory corruption, sandbox escapes, use‑after‑free bugs, JIT miscompilation, and other issues that could enable remote code execution or privilege escalation. Given the number and seriousness of these fixes — 16 high‑severity issues among them —

Citrix Warns: Patch NetScaler ADC and Gateway Flaws Immediately

Citrix Warns: Patch NetScaler ADC and Gateway Flaws Immediately

Citrix has released urgent security updates for NetScaler ADC and NetScaler Gateway after discovering two vulnerabilities that could expose sensitive session data and cause session mix-ups. The company is urging administrators to apply the fixes as soon as possible, citing the potential for exploitation that echoes earlier high-profile memory-leak bugs that were actively abused in the wild. What happened Earlier

Microsoft .NET Out-of-Bounds Read (CVE-2026-26127) Causes Remote Denial-of-Service Risk

Microsoft .NET Out-of-Bounds Read (CVE-2026-26127) Causes Remote Denial-of-Service Risk

Microsoft has issued an emergency security update to address a newly disclosed vulnerability in the .NET ecosystem that can be triggered remotely and results in denial-of-service (DoS) conditions. The flaw, tracked as CVE-2026-26127, affects multiple .NET runtime and package versions across Windows, macOS, and Linux. Administrators and developers should prioritize applying the available patches to prevent service disruption. What the

When Local Trust Breaks: The OpenClaw 0-Click Vulnerability and What Developers Must Do Now

When Local Trust Breaks: The OpenClaw 0-Click Vulnerability and What Developers Must Do Now

The speed at which developer-facing AI agents have been adopted is staggering — and rapid adoption often outpaces secure design. A recent, high-impact vulnerability in OpenClaw demonstrates how a single innocuous browser visit can be transformed into a full agent takeover. For developers and security teams, this is a reminder that conveniences like “localhost-first” assumptions carry real risk. This post