Compiled from 52 monitored sources · 73 articles reviewed
Today’s Briefing
Four critical Apache CVEs disclosed today: CVE-2026-84939 in FreeMarker allows path traversal when an attacker can supply a malformed locale identifier, CVE-2026-56207 in Impala permits SAML bearer token forgery on the hs2-http interface, and CVE-2026-41871 and CVE-2026-41869 in Nutch Server expose the REST API to unsafe reflection and resource exhaustion attacks. All four affect current production versions and Apache has published patches. Separately, two critical Chrome flaws.CVE-2026-87654, a buffer overflow in ANGLE on Windows, and CVE-2026-87650, an out of bounds read in WebGL.were patched in Chrome 153.0.8010.36.
Top Stories
- AWS puts AI vulnerability detection to the test, and false positives pile up
- Turn it off and on again, but for critical infrastructure
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.