NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
Summary
Hide ▲
Show ▼
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affected range is every version before 4.14.0, so administrators need to move off vulnerable releases now. Public exploit code was published with the disclosure, increasing pressure to upgrade quickly.
Related Happenings
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Adobe security patch release for CVE-2026-48395
Security Patch Release
H score39
First: 01.08.2026 10:12
Last: 01.08.2026 10:12
Sources 1
About this happening:
Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Adobe security patch release for CVE-2026-48395
Security Patch ReleaseAbout this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch Release
H score46
First: 29.07.2026 10:47
Last: 29.07.2026 10:47
Sources 1
About this happening:
Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
Gitea 1.27.1 security patch release for CVE-2026-60004
Security Patch ReleaseAbout this happening: Gitea's 1.27.1 security patch release closes CVE-2026-60004, a critical RCE affecting Gitea versions 1.17 through 1.27.0. The fix requires upgrading to 1.27.1,...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Timeline
-
24.07.2026 10:41 2 articles · 13d ago
NodeBB discloses eight high-severity flaws and urges upgrade to 4.14.2
Initial DisclosureAikido Security disclosed eight high-severity flaws in NodeBB after its AI pentest agents found them in a six-hour source-code review, and exploit code was published alongside the disclosure. NodeBB said it had fixed the issues, advised administrators to move to 4.14.2 released July 23, and noted that every version before 4.14.0 is affected.
Show sources
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41