BACK TO INTEL

Archives

Classification

Clear Filter
Application Security
Network Appliances
Software
Supply Chain Security
Software Security
Web Security

FeedSoftware

Verified advisories, vulnerability disclosures, and architectural research.

CVE-2026-33634

CVE-2026-33634: Critical Supply Chain Attack on Aquasecurity Trivy Demands Immediate Action

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Trivy
View Detail
CVE-2026-3502

CVE-2026-3502: Critical Integrity Check Flaw in TrueConf Client Demands Urgent Patch

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

TrueConf Client
View Detail