Tag: cve-2024-40766

soc

CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads

Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […]

Mehr lesen →
soc

CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution

A newly disclosed flaw in 7-Zip has raised fresh concerns about malicious archive handling and user-driven exploitation. CVE-2026-14266 is a heap-based buffer overflow tied to the way 7-Zip processes XZ chunked data, and successful exploitation may allow arbitrary code execution in the context of the current user. The issue is especially important because 7-Zip remains […]

Mehr lesen →
soc

7-Zip CVE-2026-14266 RCE Risk Explained

7-Zip CVE-2026-14266 RCE Risk Explained CVE-2026-14266 is a heap-based buffer overflow in 7-Zip’s XZ decompression logic. If a user opens or extracts specially crafted compressed content with an affected 7-Zip version, t

Mehr lesen →
soc

CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild

SonicWall has patched two actively exploited zero-days affecting SMA 1000 Series secure remote access appliances. The issues are CVE-2026-15409, a critical unauthenticated SSRF flaw in the Workplace interface, and CVE-2026-15410, a post-authentication code injection flaw in the Appliance Management Console that can lead to arbitrary OS command execution as administrator under certain conditions. Public reporting […]

Mehr lesen →