Two critical Chrome flaws put users at risk on malicious websites
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
Hackers are actively exploiting CVE-2026-0768, a critical vulnerability in Langflow's code validator that allows unauthenticated remote Python code execution with a CVSS score of 9.8. The flaw affects all versions of the AI-focused low-code platform and specifically impacts the custom component editor. Organizations running Langflow should prioritize patching to prevent code execution attacks.
Read full article at Security Affairs ↗Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
SonicWall has patched two zero-day vulnerabilities affecting its SMA 1000 VPN appliances that are being actively exploited in the wild. The flaws, including a critical pre-authentication SSRF vulnerability with a CVSS score of 10.0, may be chained together by attackers to compromise affected systems. Security updates are now available to address these issues discovered during SonicWall's internal security review.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek.
Two vulnerabilities in GeoNetwork can be chained together to achieve unauthenticated remote code execution against the open-source geospatial metadata catalog commonly deployed behind government and agency geoportals. The project released fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, with vulnerability details publicly disclosed on August 31.