Sources
Additional media









Progress Software has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Telerik Report Server, identified as CVE-2024-6327, which carries a CVSS score of 9.9. This flaw poses a significant risk to organizations, potentially allowing unauthorized access to sensitive data and systems. Users are urged to update their Telerik Report Server installations promptly to mitigate this risk. Additionally, a separate critical vulnerability was discovered in the Docker Engine, designated CVE-2024-41110, which has a CVSS score of 10.0. This flaw allows attackers to bypass authorization plugins, leading to severe privilege escalation across multiple Docker versions. Furthermore, the Internet Systems Consortium (ISC) has released patches for several vulnerabilities in BIND 9 DNS software, which could be exploited to cause denial-of-service (DoS) conditions, affecting server performance and availability. These developments highlight ongoing cybersecurity challenges across various software platforms.
Progress discloses second critical flaw in Telerik Report Server in as many months https://t.co/muelvW91jH
BIND updates fix four high-severity DoS bugs in the DNS software suite: https://t.co/6ocxtjBcIp by Security Affairs #infosec #cybersecurity #technology #news
Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk https://t.co/MCJ9MCCDSl