Security news.
Today's security news features multiple critical vulnerabilities and active exploitation, alongside significant developments in AI's role in cybersecurity. Several platforms, including vBulletin, OpenWrt, Arista VeloCloud Orchestrator, and JetBrains TeamCity, have urgent patches addressing severe flaws, with some already under attack. The expanding influence of AI is also highlighted, from assisting in exploit development to its emerging role in post-quantum cryptography research.
vBulletin Fixes Critical Pre-Auth RCE Flaw with Public Exploit
A critical vulnerability in vBulletin forum software (CVE-2026-62024) allows unauthenticated attackers to execute arbitrary PHP code, with a public exploit now available.
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has released version 24.10.8 to patch a critical DHCPv6 stack overflow (CVE-2026-53921) that allows unauthenticated attackers to achieve arbitrary code execution as root.
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains urges on-premise TeamCity users to update to versions 2025.11.7 or 2026.1.3 to address CVE-2026-63077, a critical flaw allowing unauthenticated arbitrary code execution.
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity OS command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited, allowing arbitrary code execution.
Hackers Target US Firms in FastJson RCE Zero-Day Attacks
Hackers are actively exploiting an unpatched remote code execution vulnerability in the FastJson open-source Java library, allowing attacks without authentication under default configurations.
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory during an evaluation, leading to privilege escalation and lateral movement.
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic's Claude Mythos Preview AI helped develop an end-to-end key-recovery attack against HAWK-256 and significantly sped up an attack on seven-round AES-128.
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Researchers found over 24,000 internet-exposed Baseboard Management Controllers (BMCs) are leaking password-derived authentication hashes before login due to a decades-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol.