<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News - Newest: &#34;CVE&#34;</title><link>https://news.ycombinator.com/newest</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 07 Sep 2026 00:17:13 +0000</lastBuildDate><atom:link href="https://hnrss.org/newest?q=CVE" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Ask HN: Why is HN censoring this post about CVE-2026-85046?]]></title><description><![CDATA[
<p>https://nordstjernen.org/cve-2026-85046-northstar.html</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49587543">https://news.ycombinator.com/item?id=49587543</a></p>
<p>Points: 2</p>
<p># Comments: 2</p>
]]></description><pubDate>Sun, 06 Sep 2026 15:36:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=49587543</link><dc:creator>roschdal</dc:creator><comments>https://news.ycombinator.com/item?id=49587543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49587543</guid></item><item><title><![CDATA[Breaking GitLab's GraphQL Layer: CVE-2026–19478 and CVE-2026–19650]]></title><description><![CDATA[
<p>Article URL: <a href="https://medium.com/peakcyber/breaking-gitlabs-graphql-layer-cve-2026-19478-cve-2026-19650-acf16e43b3dc">https://medium.com/peakcyber/breaking-gitlabs-graphql-layer-cve-2026-19478-cve-2026-19650-acf16e43b3dc</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49581172">https://news.ycombinator.com/item?id=49581172</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 05 Sep 2026 22:07:23 +0000</pubDate><link>https://medium.com/peakcyber/breaking-gitlabs-graphql-layer-cve-2026-19478-cve-2026-19650-acf16e43b3dc</link><dc:creator>syumei</dc:creator><comments>https://news.ycombinator.com/item?id=49581172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49581172</guid></item><item><title><![CDATA[Government Rails Site Hit Hours After CVE Patch]]></title><description><![CDATA[
<p>Article URL: <a href="https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/">https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49568828">https://news.ycombinator.com/item?id=49568828</a></p>
<p>Points: 114</p>
<p># Comments: 35</p>
]]></description><pubDate>Fri, 04 Sep 2026 19:06:39 +0000</pubDate><link>https://rietta.com/blog/ruby-on-rails-cve-exploited-hours-after-patch/</link><dc:creator>rietta</dc:creator><comments>https://news.ycombinator.com/item?id=49568828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49568828</guid></item><item><title><![CDATA[Vectra – Offline CVE and GTFOBins intelligence engine for your terminal]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/addisabrham36-boop/vectra">https://github.com/addisabrham36-boop/vectra</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49565823">https://news.ycombinator.com/item?id=49565823</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 04 Sep 2026 15:11:31 +0000</pubDate><link>https://github.com/addisabrham36-boop/vectra</link><dc:creator>Portzer0</dc:creator><comments>https://news.ycombinator.com/item?id=49565823</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49565823</guid></item><item><title><![CDATA[A CVE Dispute]]></title><description><![CDATA[
<p>Article URL: <a href="https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/">https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49508290">https://news.ycombinator.com/item?id=49508290</a></p>
<p>Points: 190</p>
<p># Comments: 54</p>
]]></description><pubDate>Mon, 31 Aug 2026 11:13:17 +0000</pubDate><link>https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/</link><dc:creator>theanonymousone</dc:creator><comments>https://news.ycombinator.com/item?id=49508290</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49508290</guid></item><item><title><![CDATA[Critical CVE: JFrog Artifactory Authentication Bypass]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.cve.org/CVERecord?id=CVE-2026-82329">https://www.cve.org/CVERecord?id=CVE-2026-82329</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49502508">https://news.ycombinator.com/item?id=49502508</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 30 Aug 2026 20:37:07 +0000</pubDate><link>https://www.cve.org/CVERecord?id=CVE-2026-82329</link><dc:creator>mellosouls</dc:creator><comments>https://news.ycombinator.com/item?id=49502508</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49502508</guid></item><item><title><![CDATA[CVE-2026-18963 – Keycloak Reset-Credentials Bypass → Account Takeover]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/Red-Darkin/CVE-2026-18963-keycloak">https://github.com/Red-Darkin/CVE-2026-18963-keycloak</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49441617">https://news.ycombinator.com/item?id=49441617</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 25 Aug 2026 22:35:16 +0000</pubDate><link>https://github.com/Red-Darkin/CVE-2026-18963-keycloak</link><dc:creator>mqus</dc:creator><comments>https://news.ycombinator.com/item?id=49441617</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49441617</guid></item><item><title><![CDATA[Show HN: CLI tool to check n8n instances for CVE-2026-21858 credential exposure]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/Legion33shadow/legion-n8n-shield">https://github.com/Legion33shadow/legion-n8n-shield</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49360088">https://news.ycombinator.com/item?id=49360088</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 19 Aug 2026 11:29:07 +0000</pubDate><link>https://github.com/Legion33shadow/legion-n8n-shield</link><dc:creator>LegionAPI</dc:creator><comments>https://news.ycombinator.com/item?id=49360088</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49360088</guid></item><item><title><![CDATA[CVE-2026-24301: "CoSnitch" vulnerability in Microsoft Copilot]]></title><description><![CDATA[
<p>Article URL: <a href="https://cyberupdates365.com/copilot-cosnitch-cve-2026-24301/">https://cyberupdates365.com/copilot-cosnitch-cve-2026-24301/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49359560">https://news.ycombinator.com/item?id=49359560</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 19 Aug 2026 10:29:29 +0000</pubDate><link>https://cyberupdates365.com/copilot-cosnitch-cve-2026-24301/</link><dc:creator>sysadmin_diarie</dc:creator><comments>https://news.ycombinator.com/item?id=49359560</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49359560</guid></item><item><title><![CDATA[GitLab CVE-2026-19478: GraphQL authorization bypass]]></title><description><![CDATA[
<p>Article URL: <a href="https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/">https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49358155">https://news.ycombinator.com/item?id=49358155</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 19 Aug 2026 07:29:02 +0000</pubDate><link>https://techupdate24.com/gitlab-cve-2026-19478-graphql-flaw/</link><dc:creator>sysadmin_diarie</dc:creator><comments>https://news.ycombinator.com/item?id=49358155</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49358155</guid></item><item><title><![CDATA[Wallabag Full Disclosure CVSS8.5 Stored XSS+SSRF after no patched no cve]]></title><description><![CDATA[
<p>Article URL: <a href="https://infosec.exchange/@FUNFACTOR1/117093620077858014">https://infosec.exchange/@FUNFACTOR1/117093620077858014</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49301189">https://news.ycombinator.com/item?id=49301189</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 14 Aug 2026 16:41:25 +0000</pubDate><link>https://infosec.exchange/@FUNFACTOR1/117093620077858014</link><dc:creator>turbozampier</dc:creator><comments>https://news.ycombinator.com/item?id=49301189</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49301189</guid></item><item><title><![CDATA[You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))]]></title><description><![CDATA[
<p>Article URL: <a href="https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/">https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49295904">https://news.ycombinator.com/item?id=49295904</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 14 Aug 2026 08:10:08 +0000</pubDate><link>https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/</link><dc:creator>unknownhad</dc:creator><comments>https://news.ycombinator.com/item?id=49295904</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49295904</guid></item><item><title><![CDATA[A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)]]></title><description><![CDATA[
<p>Article URL: <a href="https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass">https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49273886">https://news.ycombinator.com/item?id=49273886</a></p>
<p>Points: 9</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 12 Aug 2026 15:24:19 +0000</pubDate><link>https://hellorecon.com/blog/cve-2026-18690-mongodb-symbol-type-authz-bypass</link><dc:creator>slvnx</dc:creator><comments>https://news.ycombinator.com/item?id=49273886</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49273886</guid></item><item><title><![CDATA[CVE-2026-53361 AF_Unix GC vs. MSG_PEEK use-after-free container escape]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/sgkdev/bad_garbage">https://github.com/sgkdev/bad_garbage</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49267550">https://news.ycombinator.com/item?id=49267550</a></p>
<p>Points: 13</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 12 Aug 2026 03:31:42 +0000</pubDate><link>https://github.com/sgkdev/bad_garbage</link><dc:creator>eyberg</dc:creator><comments>https://news.ycombinator.com/item?id=49267550</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49267550</guid></item><item><title><![CDATA[Expat 2.8.3 released, fixes vulnerability CVE-2026-72522]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.hartwork.org/posts/expat-2-8-3-released/">https://blog.hartwork.org/posts/expat-2-8-3-released/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49257903">https://news.ycombinator.com/item?id=49257903</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 11 Aug 2026 13:23:24 +0000</pubDate><link>https://blog.hartwork.org/posts/expat-2-8-3-released/</link><dc:creator>spyc</dc:creator><comments>https://news.ycombinator.com/item?id=49257903</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49257903</guid></item><item><title><![CDATA[CVE-2026-56852: x/text/Unicode/norm infinite loop on invalid UTF-8 (DoS)]]></title><description><![CDATA[
<p>Article URL: <a href="https://pkg.go.dev/vuln/GO-2026-5970">https://pkg.go.dev/vuln/GO-2026-5970</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49256278">https://news.ycombinator.com/item?id=49256278</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 11 Aug 2026 11:04:23 +0000</pubDate><link>https://pkg.go.dev/vuln/GO-2026-5970</link><dc:creator>refp</dc:creator><comments>https://news.ycombinator.com/item?id=49256278</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49256278</guid></item><item><title><![CDATA[CVE-2026-65400: Apple macOS Screen Sharing authentication bypass]]></title><description><![CDATA[
<p>Article URL: <a href="https://support.apple.com/en-us/148170">https://support.apple.com/en-us/148170</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49247537">https://news.ycombinator.com/item?id=49247537</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 10 Aug 2026 18:16:54 +0000</pubDate><link>https://support.apple.com/en-us/148170</link><dc:creator>lasagnafan</dc:creator><comments>https://news.ycombinator.com/item?id=49247537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49247537</guid></item><item><title><![CDATA[WordPress CVE-2026-64638 Pre-Auth XSS to RCE]]></title><description><![CDATA[
<p>Article URL: <a href="https://pwn.ai/blog/xss2shell">https://pwn.ai/blog/xss2shell</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49215218">https://news.ycombinator.com/item?id=49215218</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 07 Aug 2026 19:30:43 +0000</pubDate><link>https://pwn.ai/blog/xss2shell</link><dc:creator>thepill</dc:creator><comments>https://news.ycombinator.com/item?id=49215218</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49215218</guid></item><item><title><![CDATA[The Keychain CVE Where Every Key Fits]]></title><description><![CDATA[
<p>Article URL: <a href="https://boberito.medium.com/the-keychain-cve-where-every-key-fits-055f377618be">https://boberito.medium.com/the-keychain-cve-where-every-key-fits-055f377618be</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49213865">https://news.ycombinator.com/item?id=49213865</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 07 Aug 2026 17:45:58 +0000</pubDate><link>https://boberito.medium.com/the-keychain-cve-where-every-key-fits-055f377618be</link><dc:creator>lapcat</dc:creator><comments>https://news.ycombinator.com/item?id=49213865</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49213865</guid></item><item><title><![CDATA[Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/V4bel/Zapscape">https://github.com/V4bel/Zapscape</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49198843">https://news.ycombinator.com/item?id=49198843</a></p>
<p>Points: 86</p>
<p># Comments: 14</p>
]]></description><pubDate>Thu, 06 Aug 2026 16:24:36 +0000</pubDate><link>https://github.com/V4bel/Zapscape</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=49198843</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49198843</guid></item></channel></rss>