A Traefik Shortcut Could Let a Stranger Inherit Your Login

A specific Traefik HTTP/3 and NTLM configuration could let one client reuse a backend connection authenticated as someone else. Fixed releases and a public test are available.

A specific Traefik HTTP/3 and NTLM configuration could let one client reuse a backend connection authenticated as someone else. Fixed releases and a public test are available.

A public PoC says Nvidia’s Windows GPU components expose shared memory that any user can write. Nvidia is investigating the scope and remediation.

A public PoC claims Avast’s malware sandbox can become a route to Windows SYSTEM. Gen Digital says the privilege-escalation flaw has been fixed.

FalconFlank turns CrowdStrike Falcon’s Office macro clean-up into a path from a low-privilege Windows account to SYSTEM. The public PoC has been independently reproduced.

Elementor Pro 4.2.1 and earlier can let an unauthenticated attacker bypass form-upload validation and place executable PHP in a public directory.

Two unpatched flaws in Kaltura's HTML5 player expose local files and can give unauthenticated attackers code execution as the web-server user.

A WordPress plugin did not merely miss one permission check. Its request path could send the method allowlist, nonce check, login requirement and capability gate through an error handler that logged the failure and returned control to the caller. The…

An exploited Check Point SmartConsole flaw turned an unauthenticated application token into full management authority. A public proof of concept now reproduces the path.

A malicious notebook could turn github.dev into a GitHub OAuth-token theft path with read and write access across the developer's repositories.

Dirty Frag turned Linux kernel networking flaws into a reliable path from a low-privilege foothold to root across major distributions.