Skip to main content
Devolutions PowerShell Universal Cleartext Storage of Secret Variables Allows Local Credential Theft (CVE-2026-16802)

Scope: Devolutions PowerShell Universal Versions 2026.2.2 and Earlier (No Vault Configured

Microsoft Azure Portal Unauthenticated Information Disclosure Server-Side Patched (CVE-2026-62835)

Scope: Microsoft Azure Portal (All Tenants, Exclusively Cloud-Hosted Service)

Devolutions PowerShell Universal Authenticated Code Injection Enables Full Server Compromise (CVE-2026-16801)

Scope: Devolutions PowerShell Universal Versions 2026.2.2 and Earlier

WP Foodbakery WordPress Plugin Subscriber-Level Path Traversal Allows Arbitrary File Deletion Leading to RCE (CVE-2026-15802)

Scope: WP Foodbakery Plugin for WordPress Versions up to and Including 4.9 (No Patch Curre

Oracle July 2026 Critical Patch Update Addresses 1,235 CVEs Across E-Business Suite, HRMS, and Fusion Middleware

Scope: Oracle E-Business Suite (Including Oracle HRMS), Oracle Fusion Middleware, Oracle P

n8n Workflow Automation Platform Triple Vulnerability Chain Enables Server Takeover (CVE-2026-65591 / CVE-2026-65592 / CVE-2026-65598)

Scope: n8n Versions Prior to 1.123.64, 2.29.8, and 2.30.1 (Self-Hosted and Cloud)

Subscribe to Advisories