Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Ubuntu has released security updates addressing five critical vulnerabilities in OpenImageIO that could enable arbitrary code execution through malformed image files. The flaws span SGI, Softimage PIC, HEIF, and DPX formats, affecting multiple Ubuntu LTS releases.
Ubuntu released USN-8405-2 to address a regression in CUPS security patches that caused crashes when parsing large PPD files. The update resolves stability issues while maintaining fixes for multiple critical vulnerabilities.
Ubuntu released USN-8398-3 to address CVE-2026-49975, a denial-of-service vulnerability in nginx's HTTP/2 cookie processing that was incompletely fixed in earlier updates. The final patch resolves resource exhaustion risks without introducing the regressions that plagued previous attempts.
Ubuntu has released a security update addressing a use-after-free flaw in tmux's image cleanup routine. A local attacker could exploit this vulnerability to crash the terminal multiplexer, disrupting user sessions.
Ubuntu's ADSys service contains two HTTP/2 frame handling vulnerabilities that could allow remote attackers to trigger denial-of-service conditions. Patches are now available across affected Ubuntu LTS releases.
Two critical vulnerabilities in Ruby's Net::IMAP library allow attackers to bypass TLS encryption and inject arbitrary IMAP commands. Ubuntu has released security patches to address CVE-2026-42246 and CVE-2026-42257.
Ubuntu has released critical security updates for .NET addressing two significant vulnerabilities: improper link resolution enabling unauthorized file writes and a denial-of-service flaw in MessagePack array handling. Development teams should prioritize patching to prevent local exploitation and resource exhaustion attacks.
A critical access policy enforcement vulnerability in Mistral allows attackers to execute arbitrary code on worker nodes and steal sensitive credentials. Ubuntu has released a security update to address the flaw discovered by researchers Eduardo Gonzalez Gutierrez and Arnaud Morin.
A vulnerability in Ubuntu Kylin Software Center's D-Bus service handling could allow local attackers to escalate privileges to administrative level. The flaw stems from improper validation of user-supplied input in the privileged service interface.