Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Vulnerabilities intelligence

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork
Vulnerabilities

RHSA-2026:74174: Important: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8857-1: KCoreAddons vulnerability

The brief

A shell-quoting flaw in KCoreAddons could let hostile input become commands in applications that rely on the affected function. Ubuntu's advisory identifies KShell::quoteArgs and provides an updated package for 26.04 LTS. The described risk depends on an application passing attacker-controlled input through that method, rather than proving every installed application is exploitable.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:74370: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Vulnérabilité dans Cisco Catalyst SD-WAN (01 octobre 2026)

From the publisher

Une vulnérabilité a été découverte dans Cisco Catalyst SD-WAN. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-76504 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Mozilla Thunderbird (01 octobre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Mozilla Thunderbird. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans CPython (01 octobre 2026)

The brief

CERT-FR has issued a CPython advisory covering CVE-2026-19445 and CVE-2026-19553. It identifies remote denial of service and security-policy bypass as the potential impacts and treats installations missing the latest security fixes as affected. The notice points administrators to Python's September 30 security bulletins for the relevant patches, without naming a specific affected-version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Redmine (01 octobre 2026)

The brief

CERT-FR warns that Redmine releases before 6.1.5 in the 6.1 series and before 7.0.2 in the 7 series contain security weaknesses that can expose data or enable cross-site scripting. Its October 1 advisory identifies those two affected branches and directs operators to Redmine's security notices for the corresponding fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

RHSA-2026:74088: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74133: Moderate: kernel security, bug fix, and enhancement update

From the publisher

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74087: Important: python3.9 security update

From the publisher

An update for python3.9 is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74095: Important: rsync security, bug fix, and enhancement update

From the publisher

An update for rsync is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74085: Important: nodejs:24 security, bug fix, and enhancement update

From the publisher

An update for the nodejs:24 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74132: Moderate: kernel-rt security, bug fix, and enhancement update

From the publisher

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74084: Critical: webkit2gtk3 security update

From the publisher

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74081: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74082: Important: python3.12-lxml security update

From the publisher

An update for python3.12-lxml is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:74089: Moderate: RHEL AI 3.0 RPM runtime CVE fix - ffmpeg

The brief

Red Hat has published a Moderate-rated update for FFmpeg RPM components in RHEL AI 3.0, covering eight listed CVEs across four processor architectures. The advisory says these RPMs are internal build artifacts supported only as part of the Red Hat AI application platform. It directs administrators to apply earlier relevant errata before installing the update and following the linked installation guidance.

Source Red HatCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73998: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

RHSA-2026:74001: Important: expat security update

From the publisher

An update for expat is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

RHSA-2026:73955: Moderate: openssh security update

From the publisher

An update for openssh is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8858-1: Authen::SASL vulnerability

The brief

Ubuntu has published an update for the Authen::SASL Perl authentication library. The detailed advisory says inadequate validation of login attempts could allow unauthorized access and lists fixed packages across several Ubuntu LTS releases. Some older-release fixes require Ubuntu Pro or Legacy Support; the release-specific package table identifies the applicable update.

Source Ubuntu Security

Read full article
Vulnerabilities

USN-8859-1: ImageMagick vulnerabilities

The brief

Ubuntu's ImageMagick update addresses multiple image-processing flaws that could crash software or, for one issue, expose sensitive information. The affected releases differ by CVE, so the advisory's individual entries matter. Its package table also distinguishes fixes delivered through Ubuntu Pro's ESM Apps coverage from updates available through other channels.

Source Ubuntu Security

Read full article
Vulnerabilities

RHSA-2026:73997: Important: gvfs security update

From the publisher

An update for gvfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Source Red HatCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

USN-8855-1: GStreamer Bad Plugins vulnerability

The brief

A crafted WAV file could trigger a crash or potentially execute code through GStreamer Bad Plugins, according to Ubuntu. The defect concerns validation of multi-channel audio block sizes. Fixed packages are listed by Ubuntu release, with some supplied through extended security coverage; the advisory does not report confirmed active exploitation.

Source Ubuntu Security

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.