As noted by The Hacker News, OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921) and a range of other remotely triggerable flaws in its network services.
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering, posing a significant risk to online communities and discussion boards.
Reported by Bleeping Computer. A proof-of-concept exploit was released for a vulnerability in Windows Active Directory Certificate Services (AD CS) known as Certighost, potentially allowing authenticated attackers to compromise an entire Windows domain.