Skip to main content
We publish an analysis and a mitigation guide whenever a critical vulnerability affects the stacks our customers run — Linux kernel, web servers, databases, container orchestration, WordPress. Subscribe to this page’s RSS feed with the button above. New advisories land there as they are published, which beats remembering to check.
nginx
CVE-2026-42533 · major
A heap overflow in nginx’s two-pass script engine, reachable through a regex-based map feeding a directive that also uses a regex capture. Affects 0.9.6 through 1.31.2.The trap: the May fix for Nginx Rift (CVE-2026-42945, fixed in 1.30.1) does not cover this one. Update to 1.30.4 or 1.31.3. Read the full advisory
cPanelLiteSpeedExploited
CVE-2026-54420 · CVSS 8.5
Symlink mishandling in the LiteSpeed cPanel plugin lets an account with nothing more than FTP access escalate to root on shared hosting running CloudLinux or CageFS.In CISA’s KEV catalog since 15 June. Fixed in LiteSpeed WHM plugin 5.3.2.1. Read the full advisory
WordPressExploited
CVE-2026-63030 · CVSS 9.8
A routing confusion in the WordPress REST API batch processor, chained with an SQL injection, gives full site takeover without any credentials. Added to CISA’s KEV catalog on 21 July and exploited in the wild.Patched in 6.9.5 and 7.0.2. Read the full advisory
WordPressSupply chain
CVE-2026-18072 · CVSS 9.8
Not a bug but an intent: version 10.8.7 of a WordPress plugin with 20,000 installs shipped a hardcoded administrator backdoor. Caught in under two hours, and pulled from WordPress.org.There is no fixed version — remove the plugin. Read the full advisory
Linux kernelContainers
CVE-2026-43499 · CVSS 7.8
A use-after-free on the futex priority-inheritance path, present since 2011, turns any local user into root in about five seconds and escapes containers to the host.No runtime mitigation exists: patch the kernel and reboot. Read the full advisory
Linux kernelContainers
CVE-2026-31431
A flaw in the kernel’s cryptographic subsystem, reachable through the AF_ALG interface, lets locally-running code walk out with root. Container escape included.A module blacklist mitigates it until the kernel patch lands. Read the full advisory
ReactExploited
CVE-2025-55182 · CVSS 10.0
Unsafe deserialisation in React 19’s Flight protocol allows arbitrary code execution on the server, unauthenticated. A perfect 10.0, with active exploitation.Read the full advisory
MongoDBData leak
CVE-2025-14847
MongoDB’s network layer leaks fragments of server memory to unauthenticated clients — credentials, API keys and BSON documents among them.Read the full advisory
Redis
CVE-2025-49844
A malicious Lua script escapes the Redis sandbox through a use-after-free in the embedded engine and runs native code on the host. Public proof of concept.Read the full advisory
Kubernetes
Four chained CVEs
Four chained flaws in the Ingress NGINX controller take an unauthenticated attacker from a request to code execution, and from there to the whole cluster.Read the full advisory
CUPSLinux
CVE-2024-47076 and friends
Four chained CUPS flaws let an attacker register a malicious printer on your network and obtain code execution the moment someone prints to it.Read the full advisory
OpenSSH
CVE-2024-6387
A 2006 bug reintroduced by a regression: recent OpenSSH versions allow remote code execution as root, with no authentication.Read the full advisory
Supply chainLinux
CVE-2024-3094
A backdoor deliberately planted in xz-utils 5.6.0 and 5.6.1, targeting OpenSSH through systemd. Caught before it reached stable distributions.Read the full advisory
Hardening your servers day to day is a different exercise from reacting to a CVE. Our enhanced VPS security guide covers the tools and habits, and the WordPress hardening checklist covers the web side.