Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild.
The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution. It carries a CVSS score of 9.3 if the User-ID Authentication Portal is configured to enable access from the internet or any
Andrey Letov 维护的 Notepad++ for Mac 项目引发了商标权争议。Notepad++ 原作者侯今吾认为项目名字有误导性,将 macOS 移植版本冠名为 Notepad++ 会给人产生该项目由 Notepad++ 团队维护或是获得认可的官方 macOS 版本的印象,但事实并非如此,此举会让用户感到困惑,并面临商标侵权的风险。Letov 已将该项目重命名为 NextPad++,并使用了不同于 Notepad++ 的图标。Letov 在开发 Notepad++ for Mac 过程中还大量使用了 AI 辅助编程工具 Anthropic Claude CLI,对于后续项目维护可能会带来疑问,也潜在面临安全问题。
A vulnerability was found in Apache OpenNLP up to 2.5.8/3.0.0-M2. It has been classified as critical. The impacted element is the function ExtensionLoader of the component Model Manifest. The manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-42027. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in NixOS Nix up to 2.34.6. Affected by this issue is some unknown functionality. This manipulation causes absolute path traversal.
This vulnerability is tracked as CVE-2026-44029. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache OpenNLP up to 2.5.8/3.0.0-M2 and classified as problematic. The affected element is the function DictionaryEntryPersistor of the component Dictionary Parser. Executing a manipulation can lead to xml external entity reference.
The identification of this vulnerability is CVE-2026-40682. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.