Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk.
"This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data," the Microsoft Defender
Eligible U.S. digital asset firms and industry organizations “that meet Treasury’s criteria” will be able to receive, at no cost, the same actionable cybersecurity information Treasury regularly shares with traditional U.S. financial institutions.
A vulnerability was found in PMQS Compress::Raw::Zlib up to 2.219 on Perl. It has been declared as problematic. Affected is the function Compress::Raw in the library zlib of the component zlib. Executing a manipulation can lead to dependency on vulnerable third-party component.
This vulnerability is handled as CVE-2026-3381. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Apache ZooKeeper up to 3.8.5/3.9.4. This vulnerability affects unknown code of the component Client Configuration Handler. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-24308. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Apache ZooKeeper up to 3.8.5/3.9.4. This issue affects some unknown processing of the component ZKTrustManager. Performing a manipulation results in certificate with host mismatch.
This vulnerability is reported as CVE-2026-24281. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in EHUELS Authen::SASL::Perl::DIGEST_MD5 up to 2.1800 on Perl. The impacted element is the function rand. The manipulation results in generation of predictable numbers or identifiers.
This vulnerability is known as CVE-2025-40918. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Red Hat Process Automation 7. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Process Automation Manager. Performing a manipulation results in incorrect default permissions.
This vulnerability is known as CVE-2025-58713. Attacking locally is a requirement. No exploit is available.
A vulnerability categorized as problematic has been discovered in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2. This vulnerability affects unknown code of the component Group Member Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-4916. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.8.8/18.9.4/18.10.2. This affects an unknown function. Performing a manipulation results in improper validation of specified quantity in input.
This vulnerability is reported as CVE-2026-1092. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2. Affected is an unknown function of the component Private Project Handler. Executing a manipulation can lead to incorrect authorization.
This vulnerability is handled as CVE-2026-2619. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in GitLab Enterprise Edition up to 18.8.8/18.9.4/18.10.2. Affected by this vulnerability is an unknown functionality of the component Analytics Dashboard. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-4332. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
An Adobe Reader zero-day vulnerability is being actively exploited via malicious PDFs, allowing hackers to steal data without user interaction, with no patch available.
A vulnerability, which was classified as critical, was found in ladela Bookly Plugin up to 27.0 on WordPress. Affected by this vulnerability is an unknown functionality of the component Negative Number Handler. Executing a manipulation of the argument tips can lead to external control of assumed-immutable web parameter.
The identification of this vulnerability is CVE-2026-2519. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in fernandobt List Category Posts Plugin up to 0.94.0 on WordPress and classified as problematic. Affected by this issue is the function catlist of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-3005. Remote exploitation of the attack is possible. No exploit is available.