CVE-2026-40691: Heap overflow in Unbound, one of the most widely deployed open-source DNS resolvers with 4.7k GitHub stars.
Send one DNSCrypt query over TCP. Reply overflows the heap. Resolver crashes. Users behind it lose DNS.
Patched in v1.25.2. Found by a CyStack researcher.
An innovative #Cybersecurity company provides comprehensive and tailored solutions to combat security threats.
Product: @whitehubnet @lockerpm
- 🚨 SECURITY ADVISORY CyStack researchers responsibly disclosed 6 vulnerabilities across Oracle VM VirtualBox, Coherence & MySQL Server, all fixed in Oracle's July 2026 Critical Patch Update. For more, visit cystack.net/disclosures #CyStack #Oracle #CyberSecurity #InfoSec
- Amazing work from one of our researcher, Mr. Trung Nguyen. We discovered 2 vulnerabilities that affected recent versions of Apple's macOS. One of which is an LPE unprivileged app escalates to root. The other related to memory handling flaw in HFS: remote kernel panic and kernel
- CVE-2026-55852: TarSlip in Frappe Framework, the core platform behind ERPNext with 10.4k GitHub stars. Import a malicious package. The tar archive contains ../ paths that escape the target directory. Arbitrary file write on the server. Full RCE. Patched in v16.23.0 and
- CVE-2026-54572: Symlink path traversal in rclone, the cloud sync tool with 58.5k GitHub stars. Sync from a malicious remote with --links. Rclone writes arbitrary files on the victim's machine. Overwrite authorized_keys or crontab and you have RCE. Plus a setuid binary planting


