
Security
Cisco SD-WAN Manager bug CVE-2026-76504: one encoded character skips login
Cisco rates the API authentication bypass 9.8 and says it is exploited in the wild. There is no workaround; fixed releases are out and logs show the attempts.

Cisco rates the API authentication bypass 9.8 and says it is exploited in the wild. There is no workaround; fixed releases are out and logs show the attempts.
Build 16 is tagged. The targeted list now includes a Simple JSON API in incubator, generational Shenandoah by default, and the deprecation of the macOS/x64 port.
The Rust project warns of an ongoing campaign against maintainers of popular crates. The target is the publish token, not the laptop.
pgAdmin 4 v9.18 closes an authentication bypass and two connection-string injections that redirect the connection, and the exported password, to a host of the caller's choosing.
A process for tracking, investigating and disclosing model behaviour, plus six cases observed over the last six months.