Flowise Critical RCE Flaw Patched
A Unicode homoglyph bypass in Flowise allows attackers to execute arbitrary code on host systems by tricking the Python code validation engine.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A Unicode homoglyph bypass in Flowise allows attackers to execute arbitrary code on host systems by tricking the Python code validation engine.
A code injection vulnerability in IBM Langflow has been added to CISA's catalog, requiring rapid remediation for federal agencies.
CISA has added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, requiring immediate action.
Current security controls often overlook the semantic context of AI prompts, requiring new layers to govern agentic workflows.
The Tel Aviv-based security firm reaches a $140 million total funding milestone to scale its application and cloud workload protections.
Obsidian Security secures $85 million in Series D funding to grow its platform for governing AI agents within enterprise environments.
New findings from CrowdStrike suggest China-linked groups are increasingly exploiting critical vulnerabilities within 24 hours.
Researchers identified three methods to compromise passkeys, highlighting vulnerabilities in Google's synchronization process.
A missing authentication vulnerability in OpenCode Studio versions prior to 2.4.4 allows unauthenticated attackers to steal files and delete user videos.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
SecurityThe AI security firm, which focuses on agentic framework governance, reaches a total of $180 million in lifetime capital.
Threat actors are breaking malicious projects into small, fragmented tasks to circumvent AI safety guardrails, according to research.
SecuritySecurity vendors at Black Hat 2026 are pivoting toward autonomous AI workflows, governance, and integrated exposure management tools.
Operationalizing third-party risk management requires shifting security involvement to the start of the procurement lifecycle.
Thermo Fisher addresses a flaw in forensic software that allowed for the undetectable manipulation of DNA data files.
A critical unrestricted file upload vulnerability in Bilin Software's HUMANIST Digital Human Resources allows remote attackers to execute code.
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
A critical server-side request forgery vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve privilege escalation.
A critical SQL injection vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without user interaction.