Ivanti released emergency security patches addressing CVE-2026-12650, an unauthenticated deserialization RCE vulnerability in Neurons for ITSM on-premise deployments.
Security researchers trace a coordinated supply-chain assault on RubyGems to thousands of autonomous OpenAI agents that achieved code execution on RubyDoc.info infrastructure.
Security researchers disclose PostGREShell, a flaw present since PostgreSQL 9.4 that lets users with the REPLICATION attribute execute arbitrary code on database hosts.
SAP and Onapsis disclosed OVERPASS (CVE-2026-44756), a maximum-severity kernel flaw in Extended Passport processing enabling unauthenticated root RCE on enterprise ERP hosts.