Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-12970: Critical Fluent Bit Docker Plugin Vulnerability Patched
A critical stack-buffer overflow vulnerability in Fluent Bit's Docker input plugin has been identified as CVE-2025-12970, with a CVSS score of 8.1 (High severity). This security flaw allows attackers...
CVE-2025-11731: Critical Libxslt Type Confusion Vulnerability Threatens XSLT Processing
A newly disclosed vulnerability, tracked as CVE-2025-11731, has sent shockwaves through the cybersecurity community, exposing a critical type confusion flaw in the widely used libxslt library. This...
CVE-2025-66030: Critical Node-Forge OID Parsing Vulnerability Threatens JavaScript Security
A critical vulnerability in the widely-used JavaScript cryptography library node-forge has been disclosed, posing significant risks to thousands of applications and services that rely on...
CVE-2025-26381: Johnson Controls OpenBlue Mobile Web App Forced Browsing Vulnerability
Johnson Controls has disclosed a significant security vulnerability in its OpenBlue Mobile Web Application for OpenBlue Workplace, tracked as CVE-2025-26381, which exposes building management systems...
Sunbird DCIM Security Alert: Critical CVEs in dcTrack & Power IQ Require Immediate Patching
A critical security advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has highlighted multiple vulnerabilities in Sunbird Software's widely used Data Center...
CVE-2022-50266: Linux Kernel kprobes Vulnerability Explained
A subtle but significant vulnerability in the Linux kernel's kprobes subsystem, designated CVE-2022-50266, exposed systems to potential denial-of-service attacks through a logic error in cleanup...
Patch React RCE CVE-2025-55182 now: unauthenticated code execution threat.
A critical, maximum-severity vulnerability in React Server Components has been disclosed, allowing unauthenticated attackers to execute arbitrary code on vulnerable servers. Tracked as CVE-2025-55182...
CVE-2025-38597: One Missing Check Can Crash Your Rockchip-Powered Linux Device
A single missing null-pointer check in the Linux kernel’s display driver for Rockchip hardware can trigger a complete system crash. The vulnerability, assigned CVE-2025-38597, was disclosed on June...
CVE-2025-64506: libpng Memory Flaw Hits Windows Apps – Patch Now
A heap buffer over-read in the libpng library has been fixed, but the patch won’t reach most Windows users automatically. Tracked as CVE-2025-64506, the bug can crash applications that create PNG...
Update libpng Now: Patch 1.6.51 Prevents Malicious PNGs from Crashing Windows Apps
A newly disclosed vulnerability in the libpng image library—tracked as CVE-2025-64505—lets attackers craft PNG files that crash applications or leak heap memory, and the fix is libpng version...
CVE-2025-13510: Critical Unauthenticated Access Vulnerability in Iskra iHUB Smart Meter Gateways
A critical security vulnerability designated CVE-2025-13510 has been publicly disclosed, affecting Iskra's iHUB and iHUB Lite smart metering gateways. This flaw, with a CVSS v3.1 base score of 9.8...
Rockwell Arena CVE-2025-11918: Critical Buffer Overflow Vulnerability in DOE File Parsing
Rockwell Automation has issued a critical security advisory for its Arena Simulation software, warning users about a newly discovered stack-based buffer overflow vulnerability that could allow...