FreeRDP 3.31.0 plugs five server bugs, pre-auth RCE chain
GNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpitGNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpitDefault unauthenticated Gremlin Server plus a Groovy sandbox bypass lets remote attackers run OS commands as the dse user.
By staffA public advisory shows how default open ksqlDB, Kafka, and Connect endpoints chain into cron-based root execution with no credentials.
By staffThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceA single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.
By tarpit