ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
Wekan versions 8.31.0–8.33 published full user documents via notificationUsers, exposing bcrypt hashes and active session tokens; patch to 8.34 and revoke tokens now.
Tina4 Stack 1.0.3 allows unauthenticated attackers to download the kim.db file and perform SQL injection via the menu endpoint, creating an immediate data breach and credential compromise risk.
Emergency airspace restrictions in Falkirk require updated risk assessments and contingency planning for safety and regulatory compliance.
Critical unauthenticated file-upload RCE in Astroid Framework for Joomla (CVE-2026-21628, versions 2.0.0–3.3.10). Immediate patching, endpoint blocking and web-root hunting advised.
New Scottish regulation sets duties for magnesium L-threonate monohydrate food supplements; focus on labelling safety and compliance for UK businesses
CVE-2026-27446 lets unauthenticated attackers coerce brokers into outbound federation to rogue servers; patch to 2.52.0 or apply vendor mitigations now.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.