Every story tagged TOP Stories, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
20 stories · open in the command center
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.
A command injection vulnerability exists in the h-ui (version v0.0.25 and below) administrative API due to improper validation of the listen configuration field. When an authenticated administrator submits a value containing shell metacharacters, the application constructs nftables/iptables rule strings using fmt.Sprintf and executes them via bash -c as root. Because the listen field lacks port or format validation, arbitrary OS commands can be injected and executed with root privileges.
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.
: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match with no credential check. This issue affects Apache Jackrabbit: from 2.23.0 through 2.23.5, from 2.22.0 through 2.22.4, from 2.20.0 through 2.20.17. Users are recommended to upgrade to versions 2.23.6, 2.22.5, or 2.20.18 which fix the issue.
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Version 4.6.78 patches the issue.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
This case highlights the growing business risk around ransomware recovery services and the need for stronger vendor due diligence during a crisis. For CIOs and technology leaders, it underscores that incident-response partners, negotiators, and data-recovery providers can become a material trust and financial-control risk if their claims, methods, and billing are not independently verified. IT organizations should treat ransomware response as a governed, audited process rather than a purely technical emergency, with clear approval controls and escalation paths.
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
This high-severity CVE indicates that an authenticated attacker with specific permissions can read or write files on the platform filesystem outside intended boundaries, creating risk of data exposure, tampering, and potential escalation into broader system compromise. For CIOs and technology leaders, the business impact is potential disruption to critical services, integrity loss in platform-hosted data, and compliance exposure, so IT teams should treat this as a patch-and-mitigate priority with strict access review and monitoring.
This high-severity stored XSS flaw (CVSS 9.3) could let an unauthenticated attacker on the same network inject malicious scripts that execute in users’ browsers, creating risk of credential theft, session hijacking, and manipulation of administrative workflows. For IT organizations, the business impact is heightened exposure of internal web applications and management portals, making rapid remediation, stronger network segmentation, and rigorous input/output sanitization a priority.
A critical-severity vulnerability in Amazon Bedrock AgentCore Starter Toolkit's agent import functionality could allow improper control of generated code, creating a serious risk for organizations building or operating AI agents on AWS. For CIOs and IT leaders, this is primarily a platform-trust and supply-chain issue: if exploited, it could undermine application integrity, expose sensitive systems, and disrupt AI-enabled workflows that depend on the toolkit.
Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
A California business owner has been charged with allegedly orchestrating a $300M scheme to export restricted Nvidia AI chips to China through transshipment routes, underscoring how aggressively the U.S. is enforcing semiconductor export controls. For CIOs and technology leaders, the case highlights the strategic importance of supply-chain due diligence, customer/end-user verification, and export-control compliance as AI hardware becomes a national-security asset, not just an IT procurement item. IT and procurement organizations should expect tighter controls, more scrutiny on cross-border shipments, and greater pressure to prove that AI infrastructure purchases and partners do not create regulatory or reputational risk.
The arrest underscores how seriously U.S. authorities are enforcing restrictions on advanced AI hardware, signaling higher legal and supply-chain risk for organizations that buy, resell, or deploy NVIDIA-based systems globally. For CIOs, the story is a reminder that AI infrastructure strategy now includes export-control compliance, distributor due diligence, and traceability of chips and servers across third-party channels—especially when sourcing through international intermediaries.