Find notable cyber news and cases, enriched with sources, timelines, and signals.

NodeBB eight-flaw security patch release (4.14.2)

Security Patch Release
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affected range is every version before 4.14.0, so administrators need to move off vulnerable releases now. Public exploit code was published with the disclosure, increasing pressure to upgrade quickly.

Related Happenings

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

Adobe security patch release for CVE-2026-48395

Security Patch Release
H score39 First: 01.08.2026 10:12 Last: 01.08.2026 10:12 Sources 1

About this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...

Gitea 1.27.1 security patch release for CVE-2026-60004

Security Patch Release
H score46 First: 29.07.2026 10:47 Last: 29.07.2026 10:47 Sources 1

About this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)

Security Patch Release
H score32 First: 11.05.2026 17:30 Last: 11.05.2026 17:30 Sources 1

About this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...

Timeline

  1. 24.07.2026 10:41 2 articles · 13d ago

    NodeBB discloses eight high-severity flaws and urges upgrade to 4.14.2

    Initial Disclosure

    Aikido Security disclosed eight high-severity flaws in NodeBB after its AI pentest agents found them in a six-hour source-code review, and exploit code was published alongside the disclosure. NodeBB said it had fixed the issues, advised administrators to move to 4.14.2 released July 23, and noted that every version before 4.14.0 is affected.

    Show sources