Threat of Year 2036/2038 vulnerabilities detailed Threat actors could harness the "Year 2036 Problem" and "Year 2038 Problem" rollover vulnerabilities impacting systems using older Network Time Protocol versions and those that leverage a 32-bit integer for time storage, respectively, to prompt significant disruptions over a decade before they are actually triggered, according to SecurityWeek.
HackRead reports that Dell UnityVSA, the software-defined version of the firm's Unity storage system, has been impacted by a severe pre-auth command injection vulnerability, tracked as CVE-2025-36604, which could be exploited to enable command execution without the necessary logins.
Half a dozen security issues affecting multiple versions of Splunk Enterprise and Splunk Cloud Platform have been flagged by Splunk, the most severe of which is the high-severity unauthenticated blind server-side request forgery vulnerability, tracked as CVE-2025-20371, reports The Cyber Express.
The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog to include almost half a dozen security issues impacting GNU Bash, Smartbedded Meteobridge, Juniper ScreenOS, Jenkins, and Samsung products, Security Affairs reports.