Latest news

  1. Vulnerabilities via oss-security

    CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  2. Vulnerabilities via oss-security

    CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  3. Vulnerabilities via BleepingComputer

    Kiteworks urges 6-hour server shutdown over potential zero-day attacks

    Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving…

  4. Vulnerabilities via oss-security

    CVE-2026-82386: Apache Roller: XML external entity processing in OPML bookmark import

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…

  5. Vulnerabilities via oss-security

    CVE-2026-82385: Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.5 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…

  6. Vulnerabilities via oss-security

    CVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint

    Posted by David M. Johnson on Sep 25 Severity: Critical CVSS 3.1: 9.8 (critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…

  7. Vulnerabilities via oss-security

    CVE-2026-82383: Apache Roller: Anonymous setup action allows frontpage configuration tampering

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.2 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected versions: - Apache Roller 6.1.5…

  8. Vulnerabilities via oss-security

    CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  9. Vulnerabilities via oss-security

    CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5…

  10. Threat Intel via CyberScoop

    Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies

    A former Army soldier responsible for a series of attacks and extortion attempts on telecom companies, including AT&T, was sentenced to 70 months in prison, the Justice…

  11. Vulnerabilities via oss-security

    CVE-2026-82380: Apache Roller: CSRF protection bypass via self-generated salt validation

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 8.1 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected versions: - Apache Roller 6.1.5…

  12. Vulnerabilities via oss-security

    CVE-2026-82379: Apache Roller: WSSE digest authentication headers can be replayed

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L Affected versions: - Apache Roller 6.1.5…

  13. Vulnerabilities via oss-security

    CVE-2026-82378: Apache Roller: OAuth authorization endpoint trusts request-supplied identity

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.0 (critical) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…

  14. Vulnerabilities via oss-security

    CVE-2026-82377: Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 9.9 (critical) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected versions: - Apache Roller 6.1.5…

  15. Vulnerabilities via oss-security

    CVE-2026-82376: Apache Roller: XML external entity processing in trackback response parser

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected versions: - Apache Roller 6.1.5…

  16. Vulnerabilities via oss-security

    CVE-2026-82375: Apache Roller: Server-side request forgery via entry trackback and enclosure URLs

    Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 7.4 (high) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected versions: - Apache Roller 6.1.5…

  17. Vulnerabilities via oss-security

    CVE-2026-82348: Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups

    Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 7.7 (high) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L Affected versions: - Apache Roller 6.1.5…

  18. Threat Intel via Schneier on Security

    Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

    I feel like someone who reads this blog will want to go to this: Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on…

  19. Vulnerabilities via Security Affairs

    U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

    U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog…

  20. Ransomware via BleepingComputer

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS…